CVE Feed

    Dashboard / CVE / CVE-2022-40620

    CVE-2022-40620

    FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a malicious update package in order to gain arbitrary code execution on affected devices. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

    Published:Jan 28, 2026
    Last Modified:Mar 9, 2026
    EPS:Jan 28, 2026
    EPSS Score:0.00054
    CVSS Score:7.7

    Affected Products

    Vendor
    Netgear
    Product
    R6230
    Vendor
    Netgear
    Product
    R6230 Firmware
    Vendor
    Netgear
    Product
    R6260
    Vendor
    Netgear
    Product
    R6260 Firmware
    Vendor
    Netgear
    Product
    R7000
    Vendor
    Netgear
    Product
    R7000 Firmware
    Vendor
    Netgear
    Product
    R8900
    Vendor
    Netgear
    Product
    R8900 Firmware
    Vendor
    Netgear
    Product
    R9000
    Vendor
    Netgear
    Product
    R9000 Firmware
    Vendor
    Netgear
    Product
    Rax120
    Vendor
    Netgear
    Product
    Rax120 Firmware
    Vendor
    Netgear
    Product
    Rax120v2
    Vendor
    Netgear
    Product
    Rax120v2 Firmware
    Vendor
    Netgear
    Product
    Rbr20
    Vendor
    Netgear
    Product
    Rbr20 Firmware
    Vendor
    Netgear
    Product
    Rbr50
    Vendor
    Netgear
    Product
    Rbs20
    Vendor
    Netgear
    Product
    Rbs20 Firmware
    Vendor
    Netgear
    Product
    Rbs50
    Vendor
    Netgear
    Product
    Xr300
    Vendor
    Netgear
    Product
    Xr300 Firmware

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High