Show filters
1,188 Total Results
Displaying 131-140 of 1,188
Sort by:
Attacker Value
Unknown

CVE-2022-47208

Disclosure Date: December 16, 2022 (last updated February 24, 2025)
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
Attacker Value
Unknown

CVE-2022-4390

Disclosure Date: December 09, 2022 (last updated February 24, 2025)
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic, these restrictions do not appear to be applied to the WAN interface for IPv6. This allows arbitrary access to any services running on the device that may be inadvertently listening via IPv6, such as the SSH and Telnet servers spawned on ports 22 and 23 by default. This misconfiguration could allow an attacker to interact with services only intended to be accessible by clients on the local network.
Attacker Value
Unknown

CVE-2022-44184

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.
Attacker Value
Unknown

CVE-2022-44191

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.
Attacker Value
Unknown

CVE-2022-44198

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.
Attacker Value
Unknown

CVE-2022-44200

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.
Attacker Value
Unknown

CVE-2022-44196

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.
Attacker Value
Unknown

CVE-2022-44188

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.
Attacker Value
Unknown

CVE-2022-44190

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.
Attacker Value
Unknown

CVE-2022-44194

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.