TLS Certificate Validation Vulnerability in NETGEAR Routers and Orbi WiFi Systems
CVE-2022-40620
7.7HIGH
Key Information:
- Vendor
NETGEAR
- Vendor
- CVE Published:
- 28 January 2026
What is CVE-2022-40620?
A vulnerability has been identified in FunJSQ, a third-party module integrated into certain NETGEAR routers and Orbi WiFi Systems. This issue arises from inadequate validation of TLS certificates during the downloading of update packages through the auto-update mechanism. An attacker positioned on the network may exploit this flaw by intercepting update requests, enabling them to deliver malicious update packages. Successfully exploiting this vulnerability can lead to arbitrary code execution on the affected devices, thereby compromising their security.