Hidden functionality in NETGEAR products - CVE-2022-36429

 

Hidden functionality in NETGEAR products - CVE-2022-36429

Published: March 24, 2023


Vulnerability identifier: #VU74011
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36429
CWE-ID: CWE-912
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software within the ubus backend communications functionality. A remote administrator can use this functionality to gain full access to the application and execute arbitrary commands on the system.


Affected software

RBR750
RBR840
RBR850
RBS750
RBS840
RBS850
RBRE950
RBRE960
RBSE950
RBSE960

How to mitigate CVE-2022-36429

Install updates from vendor's website.

RBR750 - update to 4.6.14.3
RBR840 - update to 4.6.14.3
RBR850 - update to 4.6.14.3
RBS750 - update to 4.6.14.3
RBS840 - update to 4.6.14.3
RBS850 - update to 4.6.14.3
RBRE950 - update to 6.3.7.5
RBRE960 - update to 6.3.7.5
RBSE950 - update to 6.3.7.5
RBSE960 - update to 6.3.7.5

External References

Related Security Bulletins