7.5
CVE-2022-38955
- EPSS 0.31%
- Veröffentlicht 20.09.2022 18:15:10
- Zuletzt bearbeitet 28.05.2025 16:15:27
- CVE-Watchlists
- Unerledigt
An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the CRC check. A successful attack can either introduce a backdoor to the device or make the device DoS. This affects Firmware Version: 1.1.1_1.1.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Wpn824ext Firmware Version1.1.1_1.1.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.234 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| CISA-ADP | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-354 Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
https://www.netgear.com/about/security/
https://hackmd.io/%40eupX2KdkT6iNpqJUWk9p4A/SyAnOSd1s