First published: Wed Sep 07 2022(Updated: )
NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NETGEAR R6200 firmware | <=1.0.3.12_10.1.11 | |
Netgear Routers | =v2 | |
All of | ||
NETGEAR R6300 firmware | <=1.0.4.52_10.0.93 | |
NETGEAR R6300 firmware | =v2 | |
NETGEAR R6200 firmware | <=1.0.3.12_10.1.11 | |
Netgear Routers | =v2 | |
NETGEAR R6300 firmware | <=1.0.4.52_10.0.93 | |
NETGEAR R6300 firmware | =v2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-30078 is significant, as it allows remote authenticated attackers to execute arbitrary commands on the affected NETGEAR devices.
To fix CVE-2022-30078, update the firmware of your NETGEAR R6200v2 to a version newer than R6200v2-V1.0.3.12_10.1.11 or R6300v2 to a version newer than R6300v2-V1.0.4.52.
CVE-2022-30078 affects NETGEAR R6200v2 and R6300v2 firmware versions up to specified vulnerable releases.
Yes, CVE-2022-30078 can be exploited remotely by authenticated attackers taking advantage of shell metacharacters.
The potential impacts of CVE-2022-30078 include unauthorized access to device functions, data modification, and service disruption.