First published: Sat Mar 26 2022(Updated: )
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R8500 Firmware | =1.0.2.158 | |
NETGEAR R8500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27947 is a vulnerability in NETGEAR R8500 1.0.2.158 devices that allows remote authenticated users to execute arbitrary commands.
Remote authenticated users can exploit CVE-2022-27947 by using shell metacharacters in the ipv6_fix.cgi parameters.
CVE-2022-27947 has a severity rating of 8.8 (critical).
Yes, NETGEAR R8500 1.0.2.158 firmware is affected by CVE-2022-27947.
Yes, updating the firmware of NETGEAR R8500 devices to a non-vulnerable version will fix CVE-2022-27947.