Improper Authentication in NETGEAR products - #VU67145

 

Improper Authentication in NETGEAR products - #VU67145

Published: September 9, 2022


Vulnerability identifier: #VU67145
CSH Severity: Medium
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker with WiFi password or an Ethernet connection to router can bypass authentication process and gain unauthorized access to the system.


Affected software

XR300
R8900
R9000
R7000
R6260
R6230
RBR20
RBS20
RBR50
RBS50

Remediation

Install updates from vendor's website.

XR300 - update to 1.0.3.72
R8900 - update to 1.0.5.42
R9000 - update to 1.0.5.42
R7000 - update to 1.0.11.134
R6260 - update to 1.1.0.88
R6230 - update to 1.1.0.112
RBR20 - update to 2.7.2.26
RBS20 - update to 2.7.2.26
RBR50 - update to 2.7.4.26
RBS50 - update to 2.7.4.26

External References

Related Security Bulletins