Information disclosure in NETGEAR products - #VU64821
Published: June 30, 2022
Vulnerability identifier: #VU64821
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
RBR40
RBK22
LBR20
RBK50
RBK40
RBK12
XR450
LBR1020
RBR10
RBR20
RBR50
RBS10
RBS20
RBS40
RBS50
XR500
D7800
R7800
R8900
RAX10
RAX70
RAX120
XR700
R9000
RAX120v2
RBR40
RBK22
LBR20
RBK50
RBK40
RBK12
XR450
LBR1020
RBR10
RBR20
RBR50
RBS10
RBS20
RBS40
RBS50
XR500
D7800
R7800
R8900
RAX10
RAX70
RAX120
XR700
R9000
RAX120v2
Software vendor:
NETGEAR
NETGEAR
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker on the local network can gain unauthorized access to sensitive information on the system.
Remediation
Install updates from vendor's website.