Vulnerability Description
The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerability using a specially crafted URL. This affects firmware versions: V1.1.0.112_1.0.1, V1.1.0.114_1.0.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Ac1200 R6220 Firmware | 1.1.0.112_1.0.1 |
| Netgear | Ac1200 R6220 | - |
Related Weaknesses (CWE)
References
- https://github.com/dest-3/NETGEAR/tree/main/CVE-2022-47052ExploitThird Party Advisory
- https://github.com/dest-3/NETGEAR/tree/main/CVE-2022-47052ExploitThird Party Advisory
FAQ
What is CVE-2022-47052?
CVE-2022-47052 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthentic...
How severe is CVE-2022-47052?
CVE-2022-47052 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-47052?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Ac1200 R6220 Firmware, Netgear Ac1200 R6220.