Record summary

CVE-2022-29383 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubbadboycxcc/Netgear-ssl-vpn-20211222-CVE-2022-29383Repository PoCby badboycxccStars: 25Not analyzed4 files

922.6 KiB

GitHub

PoC details
GitHubcxaqhq/netgear-to-CVE-2022-29383Repository PoCby cxaqhqStars: 0Not analyzed5 files

1020.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALNETGEAR ProSafe SSL VPN firmware - SQL InjectionCVSS 9.8

NETGEAR ProSafe SSL VPN multiple firmware versions were discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL commands, potentially leading to unauthorized access, data leakage, or denial of service.

Remediation

Apply the latest firmware update provided by NETGEAR to mitigate this vulnerability.

WeaknessesCWE-89
Authorselitebaz
Template tagscve2022cvesqlinetgearroutervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:netgear:ssl312_firmware:fvs336gv2:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3