CVE-2022-40620

HIGH

NETGEAR Orbi and Router Firmware - Remote Code Execution via FunJSQ Auto-Update TLS Certificate Validation Bypass

Title source: llm
STIX 2.1

Description

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a malicious update package in order to gain arbitrary code execution on affected devices. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

Scores

CVSS v3 7.7
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (10)
netgear/r6230_firmware < 1.1.0.112
netgear/r6260_firmware < 1.1.0.88
netgear/r7000_firmware < 1.0.11.134
netgear/r8900_firmware < 1.0.5.42
netgear/r9000_firmware < 1.0.5.42
netgear/rax120_firmware < 1.2.8.40
netgear/rax120v2_firmware < 1.2.8.40
netgear/rbr20_firmware < 2.7.2.26
netgear/rbs20_firmware < 2.7.2.26
netgear/xr300_firmware < 1.0.3.72
Published Jan 28, 2026
Tracked Since Feb 18, 2026