Skip to main content
HDWSec
High

NETGEAR R6900P and R7000P: post-authentication buffer overflow (PSV-2022-0156)

Severity
High
CVSS score
8.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Vendor
NETGEAR
Product
R6900P, R7000P
Affected version(s)
R6900P and R7000P firmware prior to 1.3.3.154
Fixed version(s)
1.3.3.154 (R6900P, R7000P)
Vulnerability type
Post-authentication buffer overflow (CWE-120)
Researchers
Jean-Jamil KHALIFÉ

Presentation

NETGEAR R6900P and R7000P (Nighthawk) routers are affected by a post-authentication buffer overflow, tracked by NETGEAR as PSV-2022-0156. According to the vendor, exploitation requires an attacker to already have LAN access to the device (the WiFi password or a wired Ethernet connection). The vulnerability was discovered and reported to NETGEAR by Jean-Jamil Khalifé (HDW Sec).

Issue(s)

  • Post-authentication buffer overflow affecting NETGEAR R6900P and R7000P.
  • Exploitation requires the WiFi password or an Ethernet connection to the router (LAN access).
  • NETGEAR rates the issue High, with a CVSS base score of 8.3 (vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L). The advisory publishes this as CVSS 3.0; the base score is identical under CVSS 3.1.
  • No workaround is available. NETGEAR fixed the issue in firmware version 1.3.3.154 for both R6900P and R7000P.
  • NETGEAR did not assign a public CVE to this advisory, and no matching CVE was found on NVD/MITRE. (Note: CVE-2022-48176 covers a separate pre-authentication aws_json stack overflow, PSV-2022-0146, and does not correspond to this post-authentication issue.)

References

Our R&D hunts for vulnerabilities.

Zero-day research, reverse engineering, coordinated disclosure: discover our R&D team.