CVE-2022-40619: Command Injection
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsqaccesstoken parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40619?
CVE-2022-40619 is considered a critical vulnerability due to its potential for unauthenticated arbitrary command injection.
How do I fix CVE-2022-40619?
To fix CVE-2022-40619, update your NETGEAR router or Orbi WiFi system to the latest firmware version available for your device.
Which NETGEAR devices are affected by CVE-2022-40619?
CVE-2022-40619 affects several NETGEAR devices such as R6230, R6260, R7000, R8900, R9000, XR300, and various Orbi models.
What is the impact of exploiting CVE-2022-40619?
Exploiting CVE-2022-40619 allows attackers to execute arbitrary commands on the affected devices without authentication.
Is CVE-2022-40619 a hardware or software vulnerability?
CVE-2022-40619 is a software vulnerability located in the FunJSQ module implemented on select NETGEAR router models.