S4E just found a medium-severity finding from cookies without secure attribute security misconfiguration scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 26, 2025

CVE-2022-40619 Scanner

CVE-2022-40619 Scanner - Remote Code Execution vulnerability in NETGEAR Routers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.6k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
CVECVE-2022-40619
7.7
CVSShigh
Exploitable remotely over the internet · no authentication required.

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Scanner is designed to identify vulnerabilities within NETGEAR Routers, widely used for providing wireless internet connectivity in homes and small businesses. The routers serve as a crucial interface between users and their internet service providers, enabling various devices to connect wirelessly. They are employed by both individuals and organizations seeking reliable wireless networking solutions. Besides home use, these routers find application in offices, offering seamless network connectivity for multiple users. The devices are appreciated for their ease of installation and user-friendly interfaces. Additionally, they support various networking technologies and offer different models to cater to diverse networking needs.

The vulnerability found in NETGEAR Routers is a Remote Code Execution (RCE) issue. It poses a significant risk as it enables attackers to execute arbitrary code on affected systems potentially. This type of vulnerability is critical due to the extensive control it grants attackers over the compromised device. The vulnerability can lead to unauthorized access and control over the network and connected devices. Consequently, it can compromise the security and privacy of data being transmitted through the router. Typically, such vulnerabilities are highly sought after by attackers due to the impact they can have on network infrastructures.

The technical details of the vulnerability include a flaw in the funjsq_httpd service, which operates on TCP port 12300. The service is responsible for handling specific requests, and due to improper validation, it allows command injection. Attackers can exploit this by sending specially crafted requests that bypass authentication mechanisms. By manipulating parameters within the requests, attackers can gain unauthorized access to execute arbitrary commands. This bypasses the security feature usually enforced by the router's authentication mechanism, resulting in unauthorized RCE potential. Such exploitation typically necessitates network adjacency or access to the same local network.

When exploited, the Remote Code Execution vulnerability can have severe consequences. Attackers gain control, enabling them to manipulate network settings, intercept data, or launch further attacks on connected devices. The router's network infrastructure might be compromised, leading to unauthorized data exfiltration or service manipulation. In organizations, it can cripple network-dependent operations, potentially causing financial losses and reputational damage. The leverage obtained through RCE allows attackers to create persistent backdoors for future exploitation. Furthermore, the network becomes susceptible to ransomware and other malware, aggravating the severity of the breach.

REFERENCES

Solution Advice
  • Apply patches and firmware updates from NETGEAR to address the vulnerability.
  • Restrict access to management interfaces and TCP port 12300 to trusted IPs only.
  • Implement network monitoring to detect abnormal interactions or cmd execution.
  • Consider network segmentation to reduce exposure of vital infrastructure.
  • Conduct regular security audits on the network devices and configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.