Information disclosure in NETGEAR products - #VU61927

 

Information disclosure in NETGEAR products - #VU61927

Published: April 6, 2022


Vulnerability identifier: #VU61927
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.


Affected software

R6120
R6260
R6330
R6350
R6850
R6220
R6230
AC2100
AC2400
AC2600
R6700v2
R6900v2
R7200
R7350
R7400
R7450

Remediation

Install updates from vendor's website.

R6120 - update to 1.0.0.82
R6260 - update to 1.1.0.86
R6330 - update to 1.1.0.86
R6350 - update to 1.1.0.86
R6850 - update to 1.1.0.86
R6220 - update to 1.1.0.112
R6230 - update to 1.1.0.112
AC2100 - update to 1.2.0.90
AC2400 - update to 1.2.0.90
AC2600 - update to 1.2.0.90
R6700v2 - update to 1.2.0.90
R6900v2 - update to 1.2.0.90
R7200 - update to 1.2.0.90
R7350 - update to 1.2.0.90
R7400 - update to 1.2.0.90
R7450 - update to 1.2.0.90

External References

Related Security Bulletins