TLS Certificate Validation Vulnerability in NETGEAR Routers and Orbi WiFi Systems
CVE-2022-40620

7.7HIGH

Key Information:

Vendor

NETGEAR

Vendor
CVE Published:
28 January 2026

What is CVE-2022-40620?

A vulnerability has been identified in FunJSQ, a third-party module integrated into certain NETGEAR routers and Orbi WiFi Systems. This issue arises from inadequate validation of TLS certificates during the downloading of update packages through the auto-update mechanism. An attacker positioned on the network may exploit this flaw by intercepting update requests, enabling them to deliver malicious update packages. Successfully exploiting this vulnerability can lead to arbitrary code execution on the affected devices, thereby compromising their security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.