CVE-2022-40620Disclosure(netgear / r6230)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a malicious update package in order to gain arbitrary code execution on affected devices. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • r6230
  • r6230_firmware
  • r6260
  • r6260_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
r6230r6230_firmwarer6260r6260_firmwarer7000r7000_firmwarer8900r8900_firmwarer9000r9000_firmware

1 version affected across 20 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-28: 1Technical Details · 2026-01-28: 101-28
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2022-40620 FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages th… https://www.cve.org/CVERecord?id=CVE-2022-40620

    Post summary

    The text reports that CVE‑2022‑40620 exposes a TLS certificate validation flaw in a Netgear third‑party module, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    00000239
    56.5K followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
HWnetgearr6230---
OSnetgearr6230_firmware---
HWnetgearr6260---
OSnetgearr6260_firmware---
HWnetgearr7000---
OSnetgearr7000_firmware---
HWnetgearr8900---
OSnetgearr8900_firmware---
HWnetgearr9000---
OSnetgearr9000_firmware---
HWnetgearrax120---
OSnetgearrax120_firmware---
HWnetgearrax120v2---
OSnetgearrax120v2_firmware---
HWnetgearrbr20---
OSnetgearrbr20_firmware---
HWnetgearrbs20---
OSnetgearrbs20_firmware---
HWnetgearxr300---
OSnetgearxr300_firmware---

Explore more