Presentation
The NETGEAR Nighthawk R7000P is a dual-band Wi-Fi home router. Jean-Jamil Khalifé (HDW Sec) reported multiple post-authentication security vulnerabilities affecting this model. NETGEAR acknowledged the report under advisory references PSV-2022-0144 and PSV-2022-0145 and released a firmware update that fixes the issues.
Issue(s)
- Multiple security vulnerabilities affect the NETGEAR R7000P, tracked by the vendor as PSV-2022-0144 and PSV-2022-0145.
- The vulnerabilities are post-authentication: NETGEAR states that exploitation requires the attacker to already have the Wi-Fi password or a wired (Ethernet) connection to the router.
- NETGEAR rates the impact as High (CVSS 8.0), with full impact on confidentiality, integrity, and availability.
- No workaround is available. Upgrading to the fixed firmware is the only remediation.
- Affected: firmware versions prior to 1.3.3.152. Fixed in 1.3.3.152.
Note on CVE and CVSS: no public CVE identifier could be reliably confirmed for these PSV references, so the CVE list is left empty. The CVSS score and vector shown here are the ones published by NETGEAR (a CVSS 3.0 base score of 8.0), reused as the CVSS 3.1 equivalent because the metric values are identical. The vendor advisory does not disclose the specific technical class of each vulnerability.