Authentication Bypass Vulnerability in NETGEAR WAC104 Devices
CVE-2021-35973
9.8CRITICAL
What is CVE-2021-35973?
The vulnerability in NETGEAR WAC104 devices allows unauthenticated attackers to manipulate HTTP queries by using the ¤tsetting.htm substring. This lets attackers change critical configurations, such as the web UI password, and can lead to enabling debug mode, which provides the limited-user account shell access. Due to inadequate permission controls in the /etc/ directory, attaining root access is relatively straightforward. This poses a significant risk to the integrity and security of network configurations.