Configuration in NETGEAR products - #VU87968
Published: April 2, 2024
Vulnerability identifier: #VU87968
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-16
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The issue may allow a remote attacker to bypass implemented security restrictions.
The issue exists due to the possibility to a security misconfiguration issue. A remote attacker on the local network can gain access to the target application.
Affected software
C6300v2
RBK852
RBR850
RBS850
CBR750
RBK852
RBR850
RBS850
CBR750
Remediation
Install updates from vendor's website.
C6300v2 - update to 1.3.13
RBK852 - update to 4.6.7.13
RBR850 - update to 4.6.7.13
RBS850 - update to 4.6.7.13
CBR750 - update to 4.6.14.4
RBK852 - update to 4.6.7.13
RBR850 - update to 4.6.7.13
RBS850 - update to 4.6.7.13
CBR750 - update to 4.6.14.4