Information Disclosure Vulnerability in NETGEAR R7450 Routers
CVE-2020-27873
6.5MEDIUM
What is CVE-2020-27873?
This vulnerability in the NETGEAR R7450 router's SOAP API allows attackers on the same network to disclose sensitive information without authentication. The flaw arises from inadequate access control mechanisms in the SOAP API, which operates on the default TCP port 80. By exploiting this weakness, unauthorized users can retrieve stored credentials, potentially leading to further compromises within the network.
Affected Version(s)
R7450 1.2.0.62_1.0.1