SOAP Interface Vulnerability in Netgear Nighthawk Router
CVE-2021-20175

7.5HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
30 December 2021

Summary

The Netgear Nighthawk R6700 router, specifically version 1.0.4.120, has a significant security vulnerability in its SOAP interface. This vulnerability arises from the use of unsecure communication methods, as all data exchanged with the SOAP interface at port 5000 is transmitted over HTTP. Consequently, sensitive information such as usernames and passwords may be exposed in plaintext, making it susceptible to interception by attackers. This flaw underlines the necessity for secure communication protocols to protect user data.

Affected Version(s)

Netgear Nighthawk R6700 1.0.4.120

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.