Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-46424

Опубликовано: 20 дек. 2022
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v0.4.1.1 and earlier.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:netgear:xwn5001_firmware:*:*:*:*:*:*:*:*
Версия до 0.4.1.1 (включая)
cpe:2.3:h:netgear:xwn5001:-:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00087
Низкий

8.1 High

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.1
github
почти 3 года назад

An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v0.4.1.1 and earlier.

EPSS

Процентиль: 26%
0.00087
Низкий

8.1 High

CVSS3

Дефекты

NVD-CWE-noinfo