Improper Authentication in NETGEAR products - #VU67145
Published: September 9, 2022
Vulnerability identifier: #VU67145
CSH Severity: Medium
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker with WiFi password or an Ethernet connection to router can bypass authentication process and gain unauthorized access to the system.
Affected software
XR300
R8900
R9000
R7000
R6260
R6230
RBR20
RBS20
RBR50
RBS50
R8900
R9000
R7000
R6260
R6230
RBR20
RBS20
RBR50
RBS50
Remediation
Install updates from vendor's website.
XR300 - update to 1.0.3.72
R8900 - update to 1.0.5.42
R9000 - update to 1.0.5.42
R7000 - update to 1.0.11.134
R6260 - update to 1.1.0.88
R6230 - update to 1.1.0.112
RBR20 - update to 2.7.2.26
RBS20 - update to 2.7.2.26
RBR50 - update to 2.7.4.26
RBS50 - update to 2.7.4.26
R8900 - update to 1.0.5.42
R9000 - update to 1.0.5.42
R7000 - update to 1.0.11.134
R6260 - update to 1.1.0.88
R6230 - update to 1.1.0.112
RBR20 - update to 2.7.2.26
RBS20 - update to 2.7.2.26
RBR50 - update to 2.7.4.26
RBS50 - update to 2.7.4.26