CVE-2022-30078
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
07/09/2022
Last modified:
14/02/2024
Description
NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameters.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:netgear:r6200_firmware:*:*:*:*:*:*:*:* | 1.0.3.12_10.1.11 (including) | |
cpe:2.3:h:netgear:r6200:v2:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:r6300_firmware:*:*:*:*:*:*:*:* | 1.0.4.52_10.0.93 (including) | |
cpe:2.3:h:netgear:r6300:v2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page