CVE-2022-27947OS Command Injection in Netgear R8500 Firmware

Severity
8.8HIGHNVD
EPSS
5.0%
top 10.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 26
Latest updateMar 27

Description

NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDnetgear/r8500_firmware1.0.2.158

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jfcp-2cmx-x8h3: NETGEAR R8500 12022-03-27
CVEList
CVE-2022-27947: NETGEAR R8500 12022-03-26
CVE-2022-27947 — OS Command Injection in Netgear | cvebase