CVE-2022-47208
Estado: ModificadaAlta (8.8)—
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.24%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
CWE
- CWE-78
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-47208",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-47208",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-17T17:31:16.838862Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vulnreport@tenable.com",
"affectedData": [
{
"vendor": "n/a",
"product": "NETGEAR Nighthawk WiFi6 Router",
"versions": [
{
"status": "affected",
"version": "NETGEAR Nighthawk WiFi6 Router prior to V1.0.9.90"
}
]
}
]
}
],
"published": "2022-12-16T20:15:08.860",
"references": [
{
"url": "https://www.tenable.com/security/research/tra-2022-37",
"tags": [
"Vendor Advisory"
],
"source": "vulnreport@tenable.com"
},
{
"url": "https://www.tenable.com/security/research/tra-2022-37",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication."
},
{
"lang": "es",
"value": "El servicio ?puhttpsniff?, que se ejecuta de forma predeterminada, es susceptible a la inyección de comandos debido a una entrada de usuario mal sanitizada. Un atacante no autenticado en el mismo segmento de red que el router puede ejecutar comandos arbitrarios en el dispositivo sin autenticación."
}
],
"lastModified": "2026-06-17T05:13:15.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:nighthawk_ax1800_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B99D0FE-39ED-4211-9E9A-7D2E691E1BFC",
"versionEndExcluding": "1.0.9.90"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:nighthawk_ax1800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1DE3A065-960D-4C5C-94BC-213136A7F346"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:nighthawk_ax2400_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB05778B-B483-410D-B840-C3BBCABDDF21",
"versionEndExcluding": "1.0.9.90"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:nighthawk_ax2400:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "268E1ED5-73FA-47D5-9E1E-7A7DDA6D2B67"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:nighthawk_ax3000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75A82842-679A-4BE5-80DA-F765C9574CA9",
"versionEndExcluding": "1.0.9.90"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:nighthawk_ax3000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E72EBF68-B0C1-4870-A53D-3BA183337706"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:nighthawk_ax5400_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "361AFE8C-CAA7-49EB-8D3E-6E40340CB9FC",
"versionEndExcluding": "1.0.9.90"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:nighthawk_ax5400:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2BE92943-95C9-4B04-AD1F-656BEB6ED20E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:nighthawk_ax6000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F80E127F-1374-4781-B4D6-720F4F48D8D4",
"versionEndExcluding": "1.0.9.90"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:nighthawk_ax6000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "18BDA466-4A39-4D20-A82A-FE3D2770F4FA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:nighthawk_ax11000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E19D5AB-C995-4155-8049-775BC8CF9051",
"versionEndExcluding": "1.0.9.90"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:nighthawk_ax11000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D8F7CDAB-F102-4B24-9561-592C36708F1D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vulnreport@tenable.com"
}