Network Misconfiguration in NETGEAR RAX30 AX2400 Series Routers
CVE-2022-4390
10CRITICAL
What is CVE-2022-4390?
Versions of the NETGEAR RAX30 AX2400 series routers prior to 1.0.9.90 exhibit a network misconfiguration where IPv6 is enabled by default on the WAN interface. While there are existing firewall restrictions for IPv4 traffic, these do not extend to IPv6 traffic, potentially exposing services such as SSH and Telnet to unauthorized access. This could allow remote attackers to interact with services that are typically restricted to local network clients, posing significant security risks.
Affected Version(s)
NETGEAR Nighthawk RAX30 NETGEAR Nighthawk WiFi6 Router prior to V1.0.9.90