Impact
This vulnerability is a weakness in input handling within the web interface of the NETGEAR JR6150 router. An administrator who is already authenticated via the local network can submit malformed data that bypasses validation checks, allowing changes to router firmware settings or device behavior. The flaw is classified as CWE-20, which reflects insufficient input validation leading to improper access control. No evidence exists that the issue has been confirmed on physical hardware; it was identified through firmware emulation in a controlled environment.
Affected Systems
Affected devices are NETGEAR JR6150 routers (AC750 WiFi Router 802.11ac Dual Band Gigabit) released in 2014. The product reached End‑of‑Support status in 2018 and no further security updates are scheduled by the vendor.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% indicates an extremely low probability of exploitation. The vulnerability is exploitable only by users that have administrator access to the local network and are able to log into the router’s web UI.
OpenCVE Enrichment