Vulnerability Details CVE-2022-46423
An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v1.2.3.7 and earlier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.5%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2022-46423
-
cpe:2.3:h:netgear:wnr2000:1.0
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.42
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.48
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.58
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.62
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.64
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.66
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.68
-
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.70
-
cpe:2.3:o:netgear:wnr2000_firmware:1.2.0.8
-
cpe:2.3:o:netgear:wnr2000_firmware:1.2.3.7