Researchers have released proof-of-concept exploits for vulnerabilities in Netgear's Orbi 750 series routers and extender satellites, one of which is a critical remote command execution flaw.

The Netgear Orbi is a popular mesh network system for home users, providing strong coverage and high performance for up to 40 simultaneously connected devices in spaces ranging from 5,000 to 12,500 square feet.
On August 30, 2022, Cisco Talos revealed the flaws in Netgear’s system and immediately notified the vendor. To ensure their products are safe from any potential threats, Netgear system users should upgrade to firmware version 4.6.14.3 as soon as possible – the update was released on January 19 of this year!
Orbi's vulnerabilities
The most serious security flaw with a CVSS v3.1 score of 9.1 is identified as CVE-2022-37337 and gives attackers the ability to execute commands remotely on Netgear Orbi routers, making it an extremely dangerous security vulnerability.
An attacker can exploit publicly accessible administrator consoles by sending a specially crafted HTTP request to the vulnerable router to execute arbitrary commands on the device.
To demonstrate the power of this vulnerability, Talos released a Proof of Concept (PoC) exploit.

Cisco's analysis uncovered another security concern—CVE-2022-38452, a high-severity remote command execution in the router's telnet service. Exploiting this flaw requires valid credentials and a related MAC address.
This is the only one of the four flaws that Netgear's January firmware update didn't address, so it remains unpatched. However, Cisco has revealed a PoC exploit for it as well.

The third security flaw, codenamed CVE-2022-36429, is a serious command injection issue in the backend communication function of the Netgear Orbi Satellite. This component connects to the router and extends the network range .
By sending a sequence of maliciously crafted JSON objects to the device, an attacker can exploit this vulnerability. However, obtaining an admin token is required to successfully execute the attack.
Finally, Cisco analysts discovered CVE-2022-38458, a cleartext transmission issue that affects the Remote Management functionality of the Netgear Orbi router, allowing man-in-the-middle attacks that can lead to the disclosure of sensitive information.
At the time of disclosure, Cisco was not aware of any active exploitation of the above flaws. However, given the availability of a PoC for CVE-2022-37337, threat actors could attempt to find misconfigured, publicly accessible routers to exploit.
The good news is that these exploits require local access, valid login credentials, or the administrator console to be publicly accessible, which makes it much more difficult to exploit the vulnerabilities.
Information source: bleepingcomputer.com
