Network Vulnerability in NETGEAR R6700v3 Router
CVE-2022-27644

5MEDIUM

Key Information:

Vendor
Netgear
Status
Vendor
CVE Published:
29 March 2023

Summary

A vulnerability exists in NETGEAR R6700v3 routers where improper validation of the certificate during HTTPS file downloads allows network-adjacent attackers to interfere with the integrity of downloaded information. The flaw does not require any form of authentication to exploit, potentially enabling attackers to leverage this issue to execute arbitrary code as root, particularly when used alongside other vulnerabilities. Users should assess their router configurations and apply available updates to enhance security defenses.

Affected Version(s)

R6700v3 1.0.4.120_10.0.91

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Denis (@0xmitsurugi) and Antide Petit (@xarkes_) from @Synacktiv
.