CVE-2022-27945

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
26/03/2022
Last modified:
31/03/2022

Description

NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:r8500_firmware:1.0.2.158:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools