Insufficient UART Console Protection in Netgear Router
CVE-2021-23147
6.8MEDIUM
Summary
The Netgear Nighthawk R6700 version 1.0.4.120 is susceptible to a vulnerability that stems from inadequate protections for its UART console. This flaw allows an attacker with physical access to the device to connect through the UART port using a serial connection. Once access is gained, the attacker can execute commands with root privileges without requiring any form of authentication, posing a significant risk to the security of the device and potentially the wider network.
Affected Version(s)
Netgear Nighthawk R6700 1.0.4.120
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved