Information Disclosure Risk in NETGEAR Multiple Routers

CVE-2021-34983

6.5MEDIUM

Key Information

Vendor
Netgear
Status
Multiple Routers
Vendor
CVE Published:
7 May 2024

Summary

A critical information disclosure vulnerability exists in multiple NETGEAR routers due to a flaw in the httpd service, which operates on TCP port 80. This weakness enables attackers within network proximity to access sensitive information without any authentication requirements. By exploiting this vulnerability, an attacker can reveal stored credentials and other sensitive configuration details, thereby facilitating further unauthorized access or compromise of the affected devices. NETGEAR has acknowledged this issue and is taking steps to address the risk across their product range.

Affected Version(s)

Multiple Routers = V1.0.11.116_10.2.100

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.