Impact
Insufficient input validation in the NETGEAR R7000 models permits an authenticated administrator on the local network to transmit malformed input that is accepted by the router’s software, enabling the attacker to alter or add configuration settings. This may result in unauthorized changes to routing rules, firewall policies, or other critical functionality, potentially compromising the integrity of the network infrastructure. The weakness is identified as CWE-20.
Affected Systems
The affected systems are all NETGEAR R7000 routers. Specific firmware versions are not enumerated, and the product is currently listed as having reached End‑of‑Support with no forthcoming security updates.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. Because the exploit requires local administrative authentication and there is no publicly available exploit code, the likelihood of exploitation is limited to insiders or attackers who have compromised local credentials. The EPSS score is not available and the vulnerability is not included in CISA’s KEV catalog, suggesting it is not widely exploited. The attack vector is local, and mitigation depends on disabling or securing administrative access.
OpenCVE Enrichment