CVE-2025-50526

9.8

Netgear · EX8000

The Netgear EX8000 range extender, specifically version 1.0.0.126, contains a command injection vulnerability in the `switch_status` function, allowing unauthenticated remote code execution.

Executive summary

Netgear EX8000 version 1.0.0.126 is vulnerable to command injection, permitting unauthenticated attackers to execute arbitrary commands on the device.

Vulnerability

The vulnerability resides in the switch_status function, which fails to sanitize user-supplied input before passing it to a system shell. This allows an unauthenticated attacker to inject and execute arbitrary system commands on the affected hardware.

Business impact

Exploitation of this vulnerability grants an attacker full administrative control over the networking device. With a CVSS score of 9.8, this could lead to the interception of network traffic, unauthorized access to internal resources, or the device being recruited into a botnet for further attacks.

Remediation

Immediate Action: Check the official Netgear support portal for firmware updates addressing this issue. If no update is available, isolate the device from public-facing network segments immediately.

Proactive Monitoring: Monitor the device's management interface logs for unauthorized access attempts or unusual configuration changes, particularly those involving the switch_status functionality.

Compensating Controls: Use network segmentation to ensure the EX8000 is not directly exposed to the internet, and disable remote management features if they are not strictly required for business operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate action to isolate affected devices. Administrators should ensure that firmware is kept current and that devices are protected by strong perimeter security, as network devices are frequent targets for persistent threat actors.

More Netgear CVEs