TLS Certificate Validation Vulnerability in NETGEAR Routers and Orbi WiFi Systems
CVE-2022-40620
Key Information:
- Vendor
NETGEAR
- Vendor
- CVE Published:
- 28 January 2026
What is CVE-2022-40620?
A vulnerability has been identified in FunJSQ, a third-party module integrated into certain NETGEAR routers and Orbi WiFi Systems. This issue arises from inadequate validation of TLS certificates during the downloading of update packages through the auto-update mechanism. An attacker positioned on the network may exploit this flaw by intercepting update requests, enabling them to deliver malicious update packages. Successfully exploiting this vulnerability can lead to arbitrary code execution on the affected devices, thereby compromising their security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved