VYPR
Unrated severityNVD Advisory· Published Nov 22, 2022· Updated Apr 29, 2025

CVE-2022-44184

CVE-2022-44184

Description

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow vulnerability in Netgear R7000P router firmware V1.3.0.8 allows remote attackers to cause a denial of service or potentially execute arbitrary code via a crafted wan_dns1_sec parameter.

Vulnerability

Netgear R7000P router firmware version V1.3.0.8 contains a buffer overflow vulnerability in the /usr/sbin/httpd binary. The overflow occurs when processing the wan_dns1_sec parameter, which is part of the WAN DNS configuration. An attacker can trigger this by sending a specially crafted HTTP request with an overly long value for wan_dns1_sec. The vulnerability is present in the affected firmware version as described in the CVE description.

Exploitation

An attacker does not require authentication to exploit this vulnerability, as the wan_dns1_sec parameter is processed by the web server (httpd) which is exposed to the network. The attacker can send a crafted HTTP request to the router's management interface, providing a long string for the wan_dns1_sec parameter. This causes a buffer overflow in the httpd process, potentially overwriting adjacent memory.

Impact

Successful exploitation of this buffer overflow could lead to a denial of service (crash of the httpd process) or, depending on the memory layout, arbitrary code execution with the privileges of the httpd process. This could allow an attacker to gain control of the router, modify its configuration, or use it as a pivot point for further attacks on the internal network.

Mitigation

As of the publication date of this CVE (2022-11-22), no official fix or security advisory from NETGEAR has been identified in the available references [1]. Users are advised to monitor NETGEAR's security page for firmware updates. If the device is no longer supported, consider replacing it with a supported model.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.