Vulnerability Details CVE-2022-46424
An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v0.4.1.1 and earlier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.3%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2022-46424
-
cpe:2.3:h:netgear:xwn5001:-
-
cpe:2.3:o:netgear:xwn5001_firmware:-
-
cpe:2.3:o:netgear:xwn5001_firmware:0.4.1.1