Authentication Bypass Vulnerability in NETGEAR Routers
CVE-2020-17409
6.5MEDIUM
What is CVE-2020-17409?
This vulnerability in certain NETGEAR routers allows network-adjacent attackers to exploit a flaw in the mini_httpd service, which listens on TCP port 80 by default. This issue arises from incorrect string matching logic when attempting to access protected pages, permitting unauthorized users to disclose stored credentials without requiring any authentication. As a result, this vulnerability poses a significant risk of further compromise within affected installations. Proper remedial actions should be considered to secure these devices.
Affected Version(s)
Multiple Routers 1.0.66