Hidden functionality in NETGEAR products - CVE-2022-38452

 

Hidden functionality in NETGEAR products - CVE-2022-38452

Published: March 24, 2023


Vulnerability identifier: #VU74012
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38452
CWE-ID: CWE-912
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software within the hidden telnet service functionality. A remote administrator can use this functionality to gain full access to the application and execute arbitrary commands on the system.


Affected software

RBR750
RBR840
RBR850
RBS750
RBS840
RBS850
RBRE950
RBRE960
RBSE950
RBSE960
RBR860
RBS860

How to mitigate CVE-2022-38452

Install updates from vendor's website.

RBR750 - update to 4.6.14.3
RBR840 - update to 4.6.14.3
RBR850 - update to 4.6.14.3
RBS750 - update to 4.6.14.3
RBS840 - update to 4.6.14.3
RBS850 - update to 4.6.14.3
RBRE950 - update to 6.3.7.10
RBRE960 - update to 6.3.7.10
RBSE950 - update to 6.3.7.10
RBSE960 - update to 6.3.7.10
RBR860 - update to 7.2.4.5
RBS860 - update to 7.2.4.5

External References

Related Security Bulletins