Description
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
Published: 2022-12-16
Score: 8.8 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-49983 The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
History

Thu, 17 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Netgear Nighthawk Ax11000 Nighthawk Ax11000 Firmware Nighthawk Ax1800 Nighthawk Ax1800 Firmware Nighthawk Ax2400 Nighthawk Ax2400 Firmware Nighthawk Ax3000 Nighthawk Ax3000 Firmware Nighthawk Ax5400 Nighthawk Ax5400 Firmware Nighthawk Ax6000 Nighthawk Ax6000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-04-17T17:31:53.707Z

Reserved: 2022-12-12T00:00:00.000Z

Link: CVE-2022-47208

cve-icon Vulnrichment

Updated: 2024-08-03T14:47:29.421Z

cve-icon NVD

Status : Modified

Published: 2022-12-16T20:15:08.860

Modified: 2025-04-17T18:15:45.287

Link: CVE-2022-47208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses