PT-2022-5715 · NetGear · Netgear R7000P
Published
2022-10-30
·
Updated
2022-11-23
·
CVE-2022-44199
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netgear R7000P version 1.3.1.64
Description
The issue is related to buffer overflow errors in the NETGEAR R7000P router's embedded software. Exploitation of this issue may allow a remote attacker to execute arbitrary code through the
openvpn server ip parameter.Recommendations
For Netgear R7000P version 1.3.1.64, consider restricting access to the
openvpn server ip parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the openvpn server ip parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear R7000P