CVE-2022-40619
published 2026-01-28CVE-2022-40619: FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This…
PriorityP181high7.7CVSS 3.1
AVNACHPRNUINSUCHIHAL
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.23%
80.8th percentile
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | r6230_firmware | < 1.1.0.112 | 1.1.0.112 |
| netgear | r6260_firmware | < 1.1.0.88 | 1.1.0.88 |
| netgear | r7000_firmware | < 1.0.11.134 | 1.0.11.134 |
| netgear | r8900_firmware | < 1.0.5.42 | 1.0.5.42 |
| netgear | r9000_firmware | < 1.0.5.42 | 1.0.5.42 |
| netgear | rax120_firmware | < 1.2.8.40 | 1.2.8.40 |
| netgear | rax120v2_firmware | < 1.2.8.40 | 1.2.8.40 |
| netgear | rbr20_firmware | < 2.7.2.26 | 2.7.2.26 |
| netgear | rbs20_firmware | < 2.7.2.26 | 2.7.2.26 |
| netgear | xr300_firmware | < 1.0.3.72 | 1.0.3.72 |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vulncheck7.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5gwm-h32x-cppq: FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devic
ghsa_unreviewed·2026-01-28
CVE-2022-40619 [HIGH] CWE-77 GHSA-5gwm-h32x-cppq: FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devic
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.
VulnCheck
NETGEAR Routers FunJSQ Vulnerability
vulncheck·2022·CVSS 7.7
CVE-2022-40619 [HIGH] NETGEAR Routers FunJSQ Vulnerability
NETGEAR Routers FunJSQ Vulnerability
A vulnerability is present in a third party module named FunJSQ, integrated on some routers and Orbi WiFi Systems. Exploitation requires an attacker to have your WiFi password or an Ethernet connection to your router.
Affected: NETGEAR NETGEAR Routers
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2026-01-26&host_type=src&vulnerability=cve-2022-40619; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2026-02-01&host_type=src&vulnerability=cve-2022-40619; https://dashboard.shadowserver.org/statistics/honeypot/vulne
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-01-28
Published
Exploited in the wild