CVE-2022-27945

HIGH

NETGEAR R8500 1.0.2.158 - Authenticated OS Command Injection via sysNewPasswd and sysConfirmPasswd Parameters

Title source: llm
STIX 2.1

Description

NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.

References (1)

Core 1
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://github.com/donothingme/VUL/blob/main/vul2/2.md

Scores

CVSS v3 8.8
EPSS 0.0500
EPSS Percentile 89.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
netgear/r8500_firmware 1.0.2.158
Published Mar 26, 2022
Tracked Since Feb 18, 2026