Vulnerability CVE-2023-28338


Published: 2023-03-15   Modified: 2023-03-16

Description:
Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a ??Content-Type? of ??multipartboundary=? will result in the request body being written to ??/tmp/mulipartFile? on the device itself. A sufficiently large file will cause device resources to be exhausted, resulting in the device becoming unusable until it is rebooted.

 References:
https://drupal9.tenable.com/security/research/tra-2023-12

Copyright 2026, cxsecurity.com

 

Back to Top