CVE-2022-30079: OS Command Injection
Published Sep 8, 2022
·Updated
Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acosservice that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.
Affected Software
4 affected components
Netgear R6200=r6200v2-v1.0.3.12
Netgear R6200=v2
All of the following
Netgear R6200=r6200v2-v1.0.3.12
Netgear R6200=v2
Event History
Sep 8, 2022
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-30079?
CVE-2022-30079 is a command injection vulnerability discovered in the Netgear R6200 v2 firmware through R6200v2-V1.0.3.12.
2
How does CVE-2022-30079 occur?
CVE-2022-30079 occurs due to a command injection vulnerability in the binary /sbin/acos_service of the Netgear R6200 v2 firmware.
3
What is the severity of CVE-2022-30079?
CVE-2022-30079 has a severity rating of 8.8, which is considered high.
4
Which software versions are affected by CVE-2022-30079?
CVE-2022-30079 affects Netgear R6200 v2 firmware through R6200v2-V1.0.3.12.
5
How can remote authenticated attackers exploit CVE-2022-30079?
Remote authenticated attackers can exploit CVE-2022-30079 to modify values in the vulnerable parameter.