HTTPd Authentication Vulnerability in NETGEAR DGN2200v1 Devices
CVE-2020-35785

8.3HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
30 December 2020

Summary

NETGEAR DGN2200v1 devices prior to version 1.0.0.60 suffer from improper handling of HTTPd authentication. This flaw could allow unauthorized users to exploit the affected devices, potentially leading to breaches in network security. Users are urged to upgrade to the latest version to mitigate the risks associated with this vulnerability. For more information, consult NETGEAR's security advisory.

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.