QSearchQSearch

CVE-2022-23650

7.2 HIGH

Netmaker is a platform for creating and managing virtual overlay networks using WireGuard

Published: 2022-02-18 · Last updated: 2026-05-18

Severity and scoring

CVSS
7.2 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-321, CWE-798

Affected products

VendorProduct
netmakernetmaker

Description

Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know the address and username of the admin. This effects the server (netmaker) component, and not clients. This has been patched in Netmaker v0.8.5, v0.9.4, and v0.10.0. There are currently no known workarounds.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-38651 Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0 (8.2 HIGH)
  • CVE-2026-29771 Netmaker makes networks with WireGuard (6.5 MEDIUM)
  • CVE-2023-32079 Netmaker makes networks with WireGuard (8.8 HIGH)
  • CVE-2023-32078 Netmaker makes networks with WireGuard (7.5 HIGH)
  • CVE-2023-32077 Netmaker makes networks with WireGuard (7.5 HIGH)

Same CWE

  • CVE-2026-22312 The device has a webserver that exposes a REST API authenticated with a constant token (8.6 HIGH)
  • CVE-2026-9260 Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier (6.2 MEDIUM)
  • CVE-2026-34029 The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastr...
  • CVE-2026-34022 The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms w...
  • CVE-2026-28742 Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image (9.8 CRITICAL)