PT-2022-5717 · NetGear · Netgear R7000P

Published

2022-10-30

·

Updated

2022-11-23

·

CVE-2022-44197

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netgear R7000P version 1.3.0.8
Description The issue is related to a buffer overflow error in the Netgear R7000P router's software. This can be exploited by a remote attacker through the openvpn server ip parameter, potentially allowing the execution of arbitrary code.
Recommendations For Netgear R7000P version 1.3.0.8, consider restricting access to the openvpn server ip parameter until a patch is available. As a temporary workaround, avoid using the openvpn server ip parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-07115
CVE-2022-44197

Affected Products

Netgear R7000P