CVE-2022-46424: High severity netgear xwn5001 firmware vulnerability
An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v0.4.1.1 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46424?
CVE-2022-46424 is a firmware modification vulnerability discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point.
How does CVE-2022-46424 work?
An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause other unauthorized actions.
Can CVE-2022-46424 be exploited remotely?
Yes, CVE-2022-46424 can be exploited remotely.
What is the severity of CVE-2022-46424?
The severity of CVE-2022-46424 is high with a CVSS score of 8.1.
How can I fix CVE-2022-46424?
To fix CVE-2022-46424, users should update their Netgear XWN5001 firmware to version 0.4.1.1 or later.