PT-2022-28121 · NetGear · Netgear Rax35+8
Fr33Rh
·
Published
2022-12-30
·
Updated
2025-04-10
·
CVE-2022-48196
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR RAX40 versions prior to 1.0.2.60
NETGEAR RAX35 versions prior to 1.0.2.60
NETGEAR R6400v2 versions prior to 1.0.4.122
NETGEAR R6700v3 versions prior to 1.0.4.122
NETGEAR R6900P versions prior to 1.3.3.152
NETGEAR R7000P versions prior to 1.3.3.152
NETGEAR R7000 versions prior to 1.0.11.136
NETGEAR R7960P versions prior to 1.4.4.94
NETGEAR R8000P versions prior to 1.4.4.94
Description
The issue is a buffer overflow that can be exploited by an unauthenticated attacker. This allows the attacker to potentially execute code with elevated privileges. The problem is similar to a previous vulnerability that allowed code execution with root privileges through manipulation on the WAN interface.
Recommendations
For RAX40 versions prior to 1.0.2.60, update to version 1.0.2.60 or later.
For RAX35 versions prior to 1.0.2.60, update to version 1.0.2.60 or later.
For R6400v2 versions prior to 1.0.4.122, update to version 1.0.4.122 or later.
For R6700v3 versions prior to 1.0.4.122, update to version 1.0.4.122 or later.
For R6900P versions prior to 1.3.3.152, update to version 1.3.3.152 or later.
For R7000P versions prior to 1.3.3.152, update to version 1.3.3.152 or later.
For R7000 versions prior to 1.0.11.136, update to version 1.0.11.136 or later.
For R7960P versions prior to 1.4.4.94, update to version 1.4.4.94 or later.
For R8000P versions prior to 1.4.4.94, update to version 1.4.4.94 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear R6400V2
Netgear R6700V3
Netgear R6900P
Netgear R7000
Netgear R7000P
Netgear R7960P
Netgear R8000
Netgear Rax35
Netgear Rax40