CVE-2022-30078: OS Command Injection
NETGEAR R6200V2 firmware versions through R6200v2-V1.0.3.1210.1.11 and R6300V2 firmware versions through R6300v2-V1.0.4.5210.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6fix.cgi ipv6wanipaddr, ipv6lanipaddr, ipv6wanlength, or ipv6lanlength parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR R6200v2 firmwareto a version that resolves this vulnerability.Fixed in R6200v2-V1.0.3.12_10.1.11 - Upgrade
Upgrade
NETGEAR R6300v2 firmwareto a version that resolves this vulnerability.Fixed in R6300v2-V1.0.4.52_10.0.93 - Compensating control
Restrict network access so remote authenticated users cannot reach the vulnerable CGI endpoint (ipv6_fix.cgi), e.g., limit access to trusted management IPs at the firewall/ACL.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30078?
The severity of CVE-2022-30078 is significant, as it allows remote authenticated attackers to execute arbitrary commands on the affected NETGEAR devices.
How do I fix CVE-2022-30078?
To fix CVE-2022-30078, update the firmware of your NETGEAR R6200v2 to a version newer than R6200v2-V1.0.3.12_10.1.11 or R6300v2 to a version newer than R6300v2-V1.0.4.52.
What NETGEAR devices are affected by CVE-2022-30078?
CVE-2022-30078 affects NETGEAR R6200v2 and R6300v2 firmware versions up to specified vulnerable releases.
Can CVE-2022-30078 be exploited remotely?
Yes, CVE-2022-30078 can be exploited remotely by authenticated attackers taking advantage of shell metacharacters.
What are the potential impacts of CVE-2022-30078?
The potential impacts of CVE-2022-30078 include unauthorized access to device functions, data modification, and service disruption.