CVE-2022-4390

Public Exploit

Description

A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic, these restrictions do not appear to be applied to the WAN interface for IPv6. This allows arbitrary access to any services running on the device that may be inadvertently listening via IPv6, such as the SSH and Telnet servers spawned on ports 22 and 23 by default. This misconfiguration could allow an attacker to interact with services only intended to be accessible by clients on the local network.

10.0
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 0.10%
Third-Party Advisory synacktiv.com
Affected: n/a NETGEAR Nighthawk RAX30
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2022-4390?
CVE-2022-4390 has been scored as a critical severity vulnerability.
How to fix CVE-2022-4390?
To fix CVE-2022-4390, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2022-4390 being actively exploited in the wild?
It is possible that CVE-2022-4390 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-4390?
CVE-2022-4390 affects n/a NETGEAR Nighthawk RAX30.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.