Impact
A command injection flaw in the firmware of certain NETGEAR Nighthawk and Orbi routers enables a network‑adjacent attacker who can act as a man‑in‑the‑middle to inject and execute arbitrary shell commands on the device. By exploiting this weakness the attacker obtains full control, compromising the confidentiality, integrity, and potentially the availability of the router. The vulnerability is classified as CWE‑295 and CWE‑77.
Affected Systems
Affected models include BE9300, MR60, MS60, R6700AX, RAX10, RAX120, RAX120v2, RAX20, RAX28, RAX29, RAX30, RAX36S, RAX43, RAX45, RAX50, RAX70, RBR760, RBS760, RS100, RS200, RS280, RS300, RS500, RS600, RS70, and RS90. Devices marked (EoS) have reached End‑of‑Support and will no longer receive security updates, so owners should retire these units and replace them with newer NETGEAR models that receive ongoing support.
Risk and Exploitability
The CVSS score of 4.9 categorizes the flaw as moderate severity. Exploitation requires an attacker to intercept and alter local network traffic, a condition that can arise in compromised or poorly segmented networks. With an EPSS score of less than 1% the likelihood of widespread exploitation is low, and the flaw is not listed in the CISA KEV catalog. However, once a man‑in‑the‑middle condition is satisfied, the attacker can execute arbitrary commands, essentially compromising the entire device.
OpenCVE Enrichment