# PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749

DevFeed: [PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749](<https://devfeed.tech/articles/pwnagent-a-one-click-wan-side-rce-in-netgear-rax-routers-with-cve-2023-24749-39683.md>)

Original publisher: [Read original article](<https://mahaloz.re/2023/02/25/pwnagent-netgear.html>)

Published: 2023-02-25T00:00:00Z

Content type: article

Language: en

Sources: [mahaloz.re](<https://devfeed.tech/sources/mahaloz-re.md>)

Topics: [bug](<https://devfeed.tech/topics/bug.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [Logging](<https://devfeed.tech/topics/logging.md>)

Tags: [bug-hunting](<https://devfeed.tech/tags/bug-hunting.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [pwn2own](<https://devfeed.tech/tags/pwn2own.md>), [rce](<https://devfeed.tech/tags/rce.md>), [routers](<https://devfeed.tech/tags/routers.md>)

## AI overview

A technical breakdown of CVE-2023-24749, a remotely accessible command-injection vulnerability in some Netgear RAX routers. The article explains how the bug can enable WAN-side remote code execution, potentially with root access, and discusses its discovery and firmware status.

## Source excerpt

A breakdown of a bug SEFCOM T0 and I exploited to achieve a WAN-side RCE in some Netgear RAX routers for pwn2own 2022. The bug is a remotely accessible command injection due to bad packet logging, cataloged as CVE-2023-24749.