Network Vulnerability in NETGEAR R6700v3 Router
CVE-2022-27644
5MEDIUM
Summary
A vulnerability exists in NETGEAR R6700v3 routers where improper validation of the certificate during HTTPS file downloads allows network-adjacent attackers to interfere with the integrity of downloaded information. The flaw does not require any form of authentication to exploit, potentially enabling attackers to leverage this issue to execute arbitrary code as root, particularly when used alongside other vulnerabilities. Users should assess their router configurations and apply available updates to enhance security defenses.
Affected Version(s)
R6700v3 1.0.4.120_10.0.91
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kevin Denis (@0xmitsurugi) and Antide Petit (@xarkes_) from @Synacktiv