Permissions, Privileges, and Access Controls in NETGEAR products - #VU61876
Published: April 5, 2022
Vulnerability identifier: #VU61876
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote administrator on the local network to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.
Affected software
SRK60
SRR60
SRS60
RBS50Y
SRC60
SXK80
SXR80
SXS80
SXK30
SXR30
SXS30
SRR60
SRS60
RBS50Y
SRC60
SXK80
SXR80
SXS80
SXK30
SXR30
SXS30
Remediation
Install updates from vendor's website.
SRK60 - update to 2.7.1.108 - Hot Fix
SRR60 - update to 2.7.1.108 - Hot Fix
SRS60 - update to 2.7.1.108 - Hot Fix
RBS50Y - update to 2.7.1.108 - Hot Fix
SRC60 - update to 2.7.1.108 - Hot Fix
SXK80 - update to 3.3.0.124 - Hot Fix
SXR80 - update to 3.3.0.124 - Hot Fix
SXS80 - update to 3.3.0.124 - Hot Fix
SXK30 - update to 4.0.0.114
SXR30 - update to 4.0.0.114
SXS30 - update to 4.0.0.114
SRR60 - update to 2.7.1.108 - Hot Fix
SRS60 - update to 2.7.1.108 - Hot Fix
RBS50Y - update to 2.7.1.108 - Hot Fix
SRC60 - update to 2.7.1.108 - Hot Fix
SXK80 - update to 3.3.0.124 - Hot Fix
SXR80 - update to 3.3.0.124 - Hot Fix
SXS80 - update to 3.3.0.124 - Hot Fix
SXK30 - update to 4.0.0.114
SXR30 - update to 4.0.0.114
SXS30 - update to 4.0.0.114