CVE-2022-47208
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.90 |
| Running on/with | Platform Versions |
|---|---|
Netgear Nighthawk Ax1800 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.90 |
| Running on/with | Platform Versions |
|---|---|
Netgear Nighthawk Ax2400 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.90 |
| Running on/with | Platform Versions |
|---|---|
Netgear Nighthawk Ax3000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.90 |
| Running on/with | Platform Versions |
|---|---|
Netgear Nighthawk Ax5400 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.90 |
| Running on/with | Platform Versions |
|---|---|
Netgear Nighthawk Ax6000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.90 |
| Running on/with | Platform Versions |
|---|---|
Netgear Nighthawk Ax11000 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.