Authentication Bypass Vulnerability in NETGEAR Routers
CVE-2020-17409

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
13 October 2020

Summary

This vulnerability in certain NETGEAR routers allows network-adjacent attackers to exploit a flaw in the mini_httpd service, which listens on TCP port 80 by default. This issue arises from incorrect string matching logic when attempting to access protected pages, permitting unauthorized users to disclose stored credentials without requiring any authentication. As a result, this vulnerability poses a significant risk of further compromise within affected installations. Proper remedial actions should be considered to secure these devices.

Affected Version(s)

Multiple Routers 1.0.66

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous
.