CVE-2022-48196
Description
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152, R7000 before 1.0.11.136, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A pre-authentication buffer overflow in multiple NETGEAR routers allows an unauthenticated attacker to potentially execute arbitrary code or cause a denial of service.
Vulnerability
A pre-authentication buffer overflow vulnerability exists in multiple NETGEAR router models, including the RAX40, RAX35, R6400v2, R6700v3, R6900P, R7000P, R7000, R7960P, and R8000P. The flaw is present in firmware versions before 1.0.2.60 (RAX40, RAX35), 1.0.4.122 (R6400v2, R6700v3), 1.3.3.152 (R6900P, R7000P), 1.0.11.136 (R7000), and 1.4.4.94 (R7960P, R8000P). An attacker can trigger the overflow without authentication, and the component affected has not been publicly disclosed [1][2].
Exploitation
An unauthenticated attacker can exploit this vulnerability with low complexity, requiring no user interaction or permissions. The attacker needs network access to the affected router to send crafted packets, which cause a buffer overflow on the device [1][2]. The specific sequence of steps has not been detailed by NETGEAR, but typical exploitation involves sending a specially crafted request to a vulnerable service listening on the router.
Impact
Successful exploitation can lead to a denial of service (device crash) or arbitrary code execution at the router's privilege level, depending on the attacker's payload [2]. This could allow an attacker to gain full control of the device, potentially enabling further attacks on the local network.
Mitigation
NETGEAR has released fixed firmware versions for all affected models: RAX40 and RAX35 to version 1.0.2.60, R6400v2 and R6700v3 to version 1.0.4.122, R6900P and R7000P to version 1.3.3.152, R7000 to version 1.0.11.136, and R7960P and R8000P to version 1.4.4.94. Users are strongly advised to update their routers to the latest firmware as soon as possible [1][2]. No other workarounds have been published, and this vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/RAX40description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.