CVE-2022-4390
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are...
Affects 2 products across 1 vendor.
A network misconfiguration in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series routers allows arbitrary access to any service due to IPv6 being enabled on the WAN interface without proper firewall restrictions.
BSID: BS-2022-GLOBAL-063954-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2022-4390?
What is the CVSS score for CVE-2022-4390?
Is CVE-2022-4390 actively exploited?
How do I remediate CVE-2022-4390?
What systems are affected by CVE-2022-4390?
| CVE ID | CVE-2022-4390 |
|---|---|
| BSID | BS-2022-GLOBAL-063954-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2022-12-09 |
| Last Modified | 2025-04-14 |
| ICS Relevance | 85% |
| Domains | |
| Source | NVD |
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic, these restrictions do not appear to be applied to the WAN interface for IPv6. This allows arbitrary access to any services running on the device that may be inadvertently listening via IPv6, such as the SSH and Telnet servers spawned on ports 22 and 23 by default. This misconfiguration could allow an attacker to interact with services only intended to be accessible by clients on the local network.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the default configuration of the router, where IPv6 is enabled on the WAN interface without corresponding firewall rules. This misconfiguration allows attackers to bypass intended security measures and gain unauthorized access to services on the network.
Exploitation Likelihood: CRITICAL
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | c3a136b345b090368b993cb2dad6e191186f723e78f77123b2b32454cfd136b4a79fa02ae3730f653278d70d9b908a116ec962ade632c0b003417ca6678edc30 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →