Command Injection Vulnerability in NETGEAR R8500 Devices
CVE-2022-27946
8.8HIGH
What is CVE-2022-27946?
NETGEAR R8500 devices running firmware version 1.0.2.158 are susceptible to a command injection vulnerability. This issue arises when remote authenticated users can manipulate shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters through the admin_account.cgi interface. By exploiting this vulnerability, attackers may execute arbitrary commands on the device, potentially compromising the system's integrity and security.