CVE-2022-27946: OS Command Injection
Published Mar 26, 2022
·Updated
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to adminaccount.cgi.
Affected Software
2 affected components
Netgear R8500 Firmware=1.0.2.158
Netgear R8500
Remediation
Patch Available
Event History
Mar 26, 2022
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27946?
CVE-2022-27946 is a vulnerability that allows remote authenticated users to execute arbitrary commands on NETGEAR R8500 1.0.2.158 devices.
2
How severe is CVE-2022-27946?
CVE-2022-27946 has a severity rating of 8.8 out of 10, which is considered critical.
3
What is the affected software version of CVE-2022-27946?
CVE-2022-27946 affects NETGEAR R8500 firmware version 1.0.2.158.
4
How can remote authenticated users exploit CVE-2022-27946?
Remote authenticated users can exploit CVE-2022-27946 by using shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi.
5
Is NETGEAR R8500 vulnerable to CVE-2022-27946?
No, NETGEAR R8500 devices are not vulnerable to CVE-2022-27946.