Firmware Modification Vulnerability in Netgear WNR2000v1 Router
CVE-2022-46423

8.1HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
20 December 2022

Summary

A firmware modification vulnerability exists in the Netgear WNR2000v1 router, enabling attackers to perform a Man-in-the-Middle (MITM) attack. This vulnerability allows adversaries to alter user-uploaded firmware images and circumvent the CRC checks, ultimately leading to potential arbitrary code execution or Denial of Service (DoS) incidents. This issue affects all versions of the firmware up to v1.2.3.7.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.