Back to overview

CVE-2022-4390

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic, these restrictions do not appear to be applied to the WAN interface for IPv6. This allows arbitrary access to any services running on the device that may be inadvertently listening via IPv6, such as the SSH and Telnet servers spawned on ports 22 and 23 by default. This misconfiguration could allow an attacker to interact with services only intended to be accessible by clients on the local network.

Metadata

CVE ID
CVE-2022-4390
State
PUBLISHED
Assigner
tenable
Reserved
2022-12-09 00:00 UTC
Published
2022-12-09 00:00 UTC
Last updated
2025-04-14 18:11 UTC
Vendor / Product
n/a / NETGEAR Nighthawk RAX30
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
n/a NETGEAR Nighthawk RAX30 NETGEAR Nighthawk WiFi6 Router prior to V1.0.9.90
Weakness (CWE)
CWESourceDescription
cna Security Misconfiguration
adp CWE-noinfo Not enough information
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview