Weak Authentication in NETGEAR CG3700b Firmware by Voo
CVE-2019-13393
7.5HIGH
Summary
The Voo-branded NETGEAR CG3700b custom firmware version 2.02.03 presents a significant security weakness due to the use of a common default passphrase for both the administrative console and the WPA2 pre-shared key. This vulnerability allows attackers to exploit weak authentication mechanisms, potentially gaining unauthorized access either through HTTP Basic Authentication methods or by targeting the WPA2 protocol. The reliance on a simplistic 8-character passphrase enables easier exploitation by malicious actors, highlighting the need for improved security measures and the immediate implementation of custom, strong passphrases.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved