NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability
CVE-2023-27370
5.7MEDIUM
What is CVE-2023-27370?
The NETGEAR RAX30 router exhibits a vulnerability related to the handling of device configuration. This issue arises from the insecure storage of configuration secrets in plaintext, which enables network-adjacent attackers to disclose sensitive information. Although exploitation requires authentication, the vulnerability allows for this mechanism to be bypassed. Attackers can leverage this flaw to gain access to stored credentials, potentially leading to further compromises in network security.
Affected Version(s)
RAX30 1.0.9.90_3