Impact
A command injection flaw in the firmware of selected NETGEAR Nighthawk and Orbi routers permits an attacker positioned on the local network to intercept and alter traffic. By injecting shell commands, the attacker can execute arbitrary commands on the device, compromising its confidentiality, integrity, and potentially availability. The weakness is classified under CWE‑295.
Affected Systems
The vulnerability affects a broad set of NETGEAR models, including BE9300, MR60, MS60, R6700AX, RAX10, RAX120, RAX120v2, RAX20, RAX28, RAX29, RAX30, RAX36S, RAX43, RAX45, RAX50, RAX70, RBR760, RBS760, RS100, RS200, RS280, RS300, RS500, RS600, RS70, and RS90. Fixed firmware versions are listed per model in the CNA solution; devices marked EoS have no further patching and should be retired.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity. Exploitation requires the attacker to be able to act as a man‑in‑the‑middle on the same local network, which is a realistic scenario in compromised or poorly segmented networks. No EPSS data is available, and the vulnerability is not listed in the KEV catalog, suggesting it is not widely exploited yet, but the attack surface remains significant because the flaw permits critical device control once the networking prerequisite is met.
OpenCVE Enrichment