Authentication Hijacking Vulnerability in NETGEAR Smart Switches
CVE-2021-40867
7.8HIGH
What is CVE-2021-40867?
Certain NETGEAR smart switches are exposed to a race-condition vulnerability allowing unauthenticated attackers to hijack an admin's login session. This vulnerability arises when an attacker shares the same source IP address as an administrator, which can occur in scenarios such as NAT environments or if the attacker already has access to the admin's machine. The multi-step HTTP authentication process utilized by these switches is inadequately secured, as it relies solely on the source IP address, thereby allowing attackers to manipulate authentication sessions and potentially gain unauthorized administrative access to the device.