CVE-2022-47209: High severity Netgear RAX30 firmware vulnerability
Published Dec 16, 2022
·Updated
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.
Affected Software
4 affected components
Netgear RAX30 firmware<1.0.9.90
Netgear RAX30
All of the following
Netgear RAX30 firmware<1.0.9.90
Netgear RAX30
Remediation
Patch Available
Event History
Dec 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-47209?
CVE-2022-47209 is a vulnerability that allows unauthorized access to a device by exploiting a backdoor support user account with a default password.
2
How severe is CVE-2022-47209?
CVE-2022-47209 has a severity rating of 8.8 (high).
3
What is the affected software version of CVE-2022-47209?
The affected software version of CVE-2022-47209 is Netgear Rax30 Firmware up to version 1.0.9.90.
4
What is the default password for the support user account in CVE-2022-47209?
The default password for the support user account in CVE-2022-47209 is 'support'.
5
How can I change the default password for the support user account in CVE-2022-47209?
There is no normally accessible means to change the default password for the support user account in CVE-2022-47209.