Information Disclosure Risk in NETGEAR Multiple Routers
CVE-2021-34983
6.5MEDIUM
Summary
A critical information disclosure vulnerability exists in multiple NETGEAR routers due to a flaw in the httpd service, which operates on TCP port 80. This weakness enables attackers within network proximity to access sensitive information without any authentication requirements. By exploiting this vulnerability, an attacker can reveal stored credentials and other sensitive configuration details, thereby facilitating further unauthorized access or compromise of the affected devices. NETGEAR has acknowledged this issue and is taking steps to address the risk across their product range.
Affected Version(s)
Multiple Routers = V1.0.11.116_10.2.100
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database