← Back

CVE-2022-47208

nvd nist
Published: Dec 16, 2022Modified: Apr 17, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.

Affected (6)

6 products
Nighthawk Ax1800 Firmware
Nighthawk Ax2400 Firmware
Nighthawk Ax3000 Firmware
Nighthawk Ax5400 Firmware
Nighthawk Ax6000 Firmware
Nighthawk Ax11000 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.9.90
Running on/withPlatform Versions
Netgear
Nighthawk Ax1800
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.9.90
Running on/withPlatform Versions
Netgear
Nighthawk Ax2400
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.9.90
Running on/withPlatform Versions
Netgear
Nighthawk Ax3000
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.9.90
Running on/withPlatform Versions
Netgear
Nighthawk Ax5400
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.9.90
Running on/withPlatform Versions
Netgear
Nighthawk Ax6000
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.9.90
Running on/withPlatform Versions
Netgear
Nighthawk Ax11000
All versions

References (2)

Source: vulnreport@tenable.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.