CVE-2022-40619Disclosure(netgear / r6230)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • r6230
  • r6230_firmware
  • r6260
  • r6260_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
r6230r6230_firmwarer6260r6260_firmwarer7000r7000_firmwarer8900r8900_firmwarer9000r9000_firmware

1 version affected across 20 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-28: 1Technical Details · 2026-01-28: 101-28
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2022-40619 FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interfa… https://www.cve.org/CVERecord?id=CVE-2022-40619

    Post summary

    CVE-2022-40619 impacts NETGEAR routers and Orbi WiFi Systems by exposing an HTTP server on the LAN interface; no exploitation, patch, or PoC details are provided.

    00000236
    56.5K followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
HWnetgearr6230---
OSnetgearr6230_firmware---
HWnetgearr6260---
OSnetgearr6260_firmware---
HWnetgearr7000---
OSnetgearr7000_firmware---
HWnetgearr8900---
OSnetgearr8900_firmware---
HWnetgearr9000---
OSnetgearr9000_firmware---
HWnetgearrax120---
OSnetgearrax120_firmware---
HWnetgearrax120v2---
OSnetgearrax120v2_firmware---
HWnetgearrbr20---
OSnetgearrbr20_firmware---
HWnetgearrbs20---
OSnetgearrbs20_firmware---
HWnetgearxr300---
OSnetgearxr300_firmware---

Explore more