HIGH🇵🇱 Wersja polska

CVE-2022-46423

CVSS 8.1v3.1pub. 2022-12-20upd. 2025-04-17

An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v1.2.3.7 and earlier.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Netgear Wnr2000

    HW
    Netgear
    1.0
  • Netgear Wnr2000 Firmware

    OS
    Netgear
    ≤ 1.2.3.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References

Related vulnerabilities

CVE-2017-6862CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w routerach NETGEAR WNR2000 umożliwia RCE bez uwierzytelnienia

CVE-2023-50089CRITICAL9.8PL ✓same product

Command Injection w NETGEAR WNR2000v4 przez SOAP over HTTP

CVE-2018-21153CRITICAL9.8PL ✓same product

NETGEAR — Pre-Authentication Buffer Overflow w routerach i extenderach

CVE-2018-21181HIGH7.2same product

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D...

CVE-2016-11059HIGH7.5same product

Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before...