Skip to main content
Mallory
HighPublic exploit

Unauthenticated Command Injection in NETGEAR/Orbi FunJSQ

IdentifiersCVE-2022-40619CWE-77· Improper Neutralization of Special…

CVE-2022-40619 affects the FunJSQ third-party module integrated into certain NETGEAR routers and Orbi WiFi systems. On affected devices, FunJSQ exposes an HTTP server on the LAN interface. The exposed interface improperly handles the funjsq_access_token parameter, allowing unauthenticated arbitrary command injection. Because the vulnerable service is reachable from the local network and does not require authentication, an attacker on the LAN can supply crafted input to execute system commands on the device. Affected products include NETGEAR R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, XR300 before 1.0.3.72, and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation permits unauthenticated arbitrary command execution on the affected router or mesh node from the LAN side. This can lead to full device compromise, modification of device configuration, malware installation, persistence, traffic interception or redirection, use of the device as a botnet node, and potential pivoting to other systems reachable from the local network.

Mitigation

If you can’t patch tonight, do this now.

Until firmware updates can be applied, restrict access to the device LAN management plane and the exposed FunJSQ HTTP service to trusted hosts only. Use network segmentation, VLANs, ACLs, and local firewall controls to prevent untrusted LAN or Wi-Fi clients from reaching the service. Limit or disable local administrative exposure where possible and prevent untrusted clients from joining the local network.

Remediation

Patch, then assume compromise.

Upgrade affected devices to fixed firmware releases or later. The provided fixed versions are: R6230 1.1.0.112+, R6260 1.1.0.88+, R7000 1.0.11.134+, R8900 1.0.5.42+, R9000 1.0.5.42+, XR300 1.0.3.72+, Orbi RBR20 2.7.2.26+, RBR50 2.7.4.26+, RBS20 2.7.2.26+, and RBS50 2.7.4.26+.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
NetgearOrbi Rbr20hardware
NetgearOrbi Rbr50hardware
NetgearOrbi Rbs20hardware
NetgearOrbi Rbs50hardware
NetgearR6230hardware
NetgearR6230 Firmwareoperating_system
NetgearR6260hardware
NetgearR6260 Firmwareoperating_system
NetgearR7000hardware
NetgearR7000 Firmwareoperating_system
NetgearR8900hardware
NetgearR8900 Firmwareoperating_system
NetgearR9000hardware
NetgearR9000 Firmwareoperating_system
NetgearRax120 Firmwareoperating_system
NetgearRax120v2 Firmwareoperating_system
NetgearRbr20 Firmwareoperating_system
NetgearRbs20 Firmwareoperating_system
NetgearXr300hardware
NetgearXr300 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity3

Community discussion across Reddit, Mastodon, and other social sources.