Presentation
NETGEAR R6900P and R7000P (Nighthawk) routers are affected by a post-authentication buffer overflow, tracked by NETGEAR as PSV-2022-0156. According to the vendor, exploitation requires an attacker to already have LAN access to the device (the WiFi password or a wired Ethernet connection). The vulnerability was discovered and reported to NETGEAR by Jean-Jamil Khalifé (HDW Sec).
Issue(s)
- Post-authentication buffer overflow affecting NETGEAR R6900P and R7000P.
- Exploitation requires the WiFi password or an Ethernet connection to the router (LAN access).
- NETGEAR rates the issue High, with a CVSS base score of 8.3 (vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L). The advisory publishes this as CVSS 3.0; the base score is identical under CVSS 3.1.
- No workaround is available. NETGEAR fixed the issue in firmware version 1.3.3.154 for both R6900P and R7000P.
- NETGEAR did not assign a public CVE to this advisory, and no matching CVE was found on NVD/MITRE. (Note: CVE-2022-48176 covers a separate pre-authentication aws_json stack overflow, PSV-2022-0146, and does not correspond to this post-authentication issue.)
References
- NETGEAR Security Advisory PSV-2022-0156: https://kb.netgear.com/000065266/Security-Advisory-for-Post-authentication-Buffer-Overflow-on-Some-Routers-PSV-2022-0156