CVE-2022-46423

CWE-4943 documents3 sources
Severity
8.1HIGH
EPSS
0.5%
top 36.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20

Description

An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v1.2.3.7 and earlier.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6662-6w2g-g564: An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router2022-12-20
CVEList
CVE-2022-46423: An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router2022-12-20
CVE-2022-46423 (HIGH CVSS 8.1) | An exploitable firmware modificatio | cvebase.io