CVE-2022-29383

CRITICAL EXPLOITED NUCLEI

NETGEAR ProSafe SSL VPN - SQL Injection

Title source: llm

Description

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

Exploits (2)

nomisec WRITEUP 27 stars
by badboycxcc · infoleak
https://github.com/badboycxcc/Netgear-ssl-vpn-20211222-CVE-2022-29383
nomisec WRITEUP
by cxaqhq · poc
https://github.com/cxaqhq/netgear-to-CVE-2022-29383

Nuclei Templates (1)

NETGEAR ProSafe SSL VPN firmware - SQL Injection
CRITICALVERIFIEDby elitebaz

Scores

CVSS v3 9.8
EPSS 0.7525
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-13
CWE
CWE-89
Status published
Products (2)
netgear/ssl312_firmware fvs336gv2
netgear/ssl312_firmware fvs336gv3
Published May 13, 2022
Tracked Since Feb 18, 2026