CVE-2022-48176

Severity
7.8HIGH
EPSS
0.1%
top 79.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31

Description

Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDnetgear/r6900p_firmware< 1.3.3.154
NVDnetgear/r7000p_firmware< 1.3.3.154
NVDnetgear/r7960p_firmware< 1.4.4.94
NVDnetgear/r8000p_firmware< 1.4.4.94
NVDnetgear/mr60_firmware< 1.1.7.132

Patches

🔴Vulnerability Details

2
GHSA
GHSA-76w4-2fg3-x9mc: Netgear routers R7000P before v12023-01-31
CVEList
CVE-2022-48176: Netgear routers R7000P before v12023-01-30
CVE-2022-48176 (HIGH CVSS 7.8) | Netgear routers R7000P before v1.3. | cvebase.io