Security features bypass in NETGEAR products - #VU62043
Published: April 11, 2022
Vulnerability identifier: #VU62043
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to security misconfiguration issue. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.
Affected software
R8500
R6400v2
R7000
R7000P
R6400v2
R7000
R7000P
Remediation
Install updates from vendor's website.
R8500 - update to 1.0.2.154
R6400v2 - update to 1.0.4.118
R7000 - update to 1.0.11.126
R7000P - update to 1.3.3.140
R6400v2 - update to 1.0.4.118
R7000 - update to 1.0.11.126
R7000P - update to 1.3.3.140