Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-4390

10.0 · CRITICAL
Published Dec 9, 2022 netgear EPSS 0.90% (57th pctl)

Overview

CVE-2022-4390 is a critical-severity vulnerability affecting netgear ax2400_firmware. It was published on December 9, 2022 and has a CVSS 3.1 base score of 10.0 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 10.0, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic, these restrictions do not appear to be applied to the WAN interface for IPv6. This allows arbitrary access to any services running on the device that may be inadvertently listening via IPv6, such as the SSH and Telnet servers spawned on ports 22 and 23 by default. This misconfiguration could allow an attacker to interact with services only intended to be accessible by clients on the local network.

Remediation

Check the references section for vendor advisories and patches from netgear. Update ax2400_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
netgear ax2400_firmware >= 0, < 1.0.9.90 Affected

Frequently Asked Questions

What is CVE-2022-4390?

CVE-2022-4390 is a critical-severity vulnerability affecting netgear ax2400_firmware. It was published on December 9, 2022 and has a CVSS 3.1 base score of 10.0 (CRITICAL).

How severe is CVE-2022-4390?

This vulnerability has a CVSS 3.1 base score of 10.0, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2022-4390?

Check the references section for vendor advisories and patches from netgear. Update ax2400_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-4390?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-4390 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.