CVE-2022-48196

Severity
9.8CRITICAL
EPSS
1.3%
top 20.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152, R7000 before 1.0.11.136, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 2.8 | Impact: 4.0

Affected Packages9 packages

NVDnetgear/r7000p_firmware< 1.3.3.152
NVDnetgear/r7000_firmware< 1.0.11.136
NVDnetgear/rax35_firmware< 1.0.2.60
NVDnetgear/rax40_firmware< 1.0.2.60
NVDnetgear/r6900p_firmware< 1.3.3.152

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qc52-6cw2-7g23: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker2022-12-30
CVEList
CVE-2022-48196: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker2022-12-30
CVE-2022-48196 (CRITICAL CVSS 9.8) | Certain NETGEAR devices are affecte | cvebase.io