CVE-2023-49693

CRITICAL

NETGEAR ProSAFE Network Management System < 1.7.0.34 - Unauthenticated Remote Code Execution via JDWP

Title source: llm
STIX 2.1

Description

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

Scores

CVSS v3 9.8
EPSS 0.0072
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
netgear/prosafe_network_management_system < 1.7.0.34
Published Nov 29, 2023
Tracked Since Feb 18, 2026