Sensitive Information Disclosure in NETGEAR D3600 and D6000 Products
CVE-2018-21136

4.6MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
23 April 2020

Summary

Certain NETGEAR modem routers, specifically the D3600 and D6000 models, are vulnerable to a security flaw that allows for the disclosure of sensitive information. This issue affects devices running firmware versions prior to 1.0.0.76, potentially exposing users to unauthorized data access or leakage. The vulnerability underscores the importance of timely firmware updates to safeguard personal and sensitive information from exploitation. For more detailed guidance, refer to the NETGEAR security advisory available on their knowledge base.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.