First published: Fri Dec 16 2022(Updated: )
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Rax30 Firmware | <1.0.9.90 | |
Netgear RAX30 | ||
All of | ||
Netgear Rax30 Firmware | <1.0.9.90 | |
Netgear RAX30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47209 is a vulnerability that allows unauthorized access to a device by exploiting a backdoor support user account with a default password.
CVE-2022-47209 has a severity rating of 8.8 (high).
The affected software version of CVE-2022-47209 is Netgear Rax30 Firmware up to version 1.0.9.90.
The default password for the support user account in CVE-2022-47209 is 'support'.
There is no normally accessible means to change the default password for the support user account in CVE-2022-47209.