Security News > 2023 > March > PoC exploits released for Netgear Orbi router vulnerabilities

PoC exploits released for Netgear Orbi router vulnerabilities
2023-03-22 14:14

Proof-of-concept exploits for vulnerabilities in Netgear's Orbi 750 series router and extender satellites have been released, with one flaw a critical severity remote command execution bug.

The first and most critical flaw is tracked as CVE-2022-37337 and is a remotely exploitable command execution vulnerability in the access control functionality of the Netgear Orbi router.

The third vulnerability is CVE-2022-36429, a high-severity command injection in the backend communications functionality of the Netgear Orbi Satellite, which links to the router to extend the network coverage.

Finally, Cisco's analysts discovered CVE-2022-38458, a cleartext transmission problem impacting the Remote Management functionality of the Netgear Orbi router, enabling man-in-the-middle attacks that can lead to sensitive information disclosure.

While Orbi does support the automatic installation of updates, on an Orbi seen by BleepingComputer, new firmware did not automatically install, and it was running software released in August 2022.

Owners of Netgear Orbi 750 devices should manually check to see if they are running the latest version, and if not, upgrade their firmware as soon as possible.


News URL

https://www.bleepingcomputer.com/news/security/poc-exploits-released-for-netgear-orbi-router-vulnerabilities/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-03-21 CVE-2022-38458 Missing Encryption of Sensitive Data vulnerability in Netgear Rbs750 Firmware 4.6.8.5
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5.
network
high complexity
netgear CWE-311
5.9
2023-03-21 CVE-2022-37337 OS Command Injection vulnerability in Netgear Rbs750 Firmware 4.6.8.5
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5.
network
low complexity
netgear CWE-78
8.8
2023-03-21 CVE-2022-36429 Hidden Functionality vulnerability in Netgear Rbs750 Firmware 4.6.8.5
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5.
network
low complexity
netgear CWE-912
7.2

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Netgear 502 8 474 462 149 1093