VYPR

R6230

by Netgear

CVEs (3)

  • CVE-2022-40620Jan 28, 2026
    risk 0.00cvss epss 0.00

    FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update…

  • CVE-2022-40619Jan 28, 2026
    risk 0.00cvss epss 0.02

    FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This…

  • CVE-2020-26929Oct 9, 2020
    risk 0.00cvss epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.