Executive brief
A security vulnerability exists in the NETGEAR WAX333 wireless access point, a device used to provide Wi-Fi connectivity in business environments. An attacker who is already logged into the device and connected to the local network could make unauthorized changes to the device's settings. This could lead to unauthorized configuration modifications, potentially impacting the security or stability of the local wireless network.
Technical details
An improper input validation vulnerability (CWE-20) exists in the NETGEAR WAX333 Access Point. The flaw allows an attacker with high privileges (PR:H) who is connected via the adjacent network (AV:A) to perform unauthorized configuration changes. The vulnerability is triggered by failing to properly validate inputs, which can be exploited by an already authenticated user to modify device settings. The issue is addressed in firmware version V2.8.0.100.
Affected products
- NETGEAR WAX333 < V2.8.0.100
Timeline
- 2026-07-14: advisory: NVD publication date
- 2026-07-14: disclosed: Initial disclosure by Netgear