Firmware Downgrade Vulnerability on Netgear WiFi Range Extender
CVE-2022-38956
5.3MEDIUM
Summary
A vulnerability has been identified in the Netgear WPN824EXT WiFi Range Extender that allows an attacker to exploit a firmware downgrade issue. This flaw can enable a man-in-the-middle (MITM) attack, where the attacker replaces a user-uploaded firmware with a previous, potentially vulnerable version. This issue affects devices running Firmware 1.1.1_1.1.9 and earlier, posing significant security risks for users relying on this equipment. It's crucial for users to remain vigilant and update their devices to mitigate potential exploitation.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved