PT-2022-5312 · NetGear · Netgear R6220

Published

2022-10-17

·

Updated

2023-08-08

·

CVE-2022-42221

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netgear R6220 version 1.1.0.114 1.0.1
Description The issue is related to incorrect access control, resulting in a command injection vulnerability. It is also described as a lack of data cleaning measures at the management level, which can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For Netgear R6220 version 1.1.0.114 1.0.1, consider restricting access to the management interface to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using any potentially vulnerable functions or parameters that could be used for command injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06614
CVE-2022-42221

Affected Products

Netgear R6220