#VU49686 Improper Authentication in Hardware solutions


Published: 2021-01-19

Vulnerability identifier: #VU49686

Vulnerability risk: Low

CVSSv3.1: 5.9 [CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: N/A

CWE-ID: CWE-287

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
AC2100
Hardware solutions / Routers for home users
AC2400
Hardware solutions / Routers for home users
AC2600
Hardware solutions / Routers for home users
R6700v2
Hardware solutions / Routers for home users
R6800
Hardware solutions / Routers for home users
R6900v2
Hardware solutions / Routers for home users
R7200
Hardware solutions / Routers for home users
R7350
Hardware solutions / Routers for home users
R7400
Hardware solutions / Routers for home users
R7450
Hardware solutions / Routers for home users
R6220
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6230
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6260
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6330
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6350
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6850
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6120
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6020
Hardware solutions / Routers & switches, VoIP, GSM, etc
R6080
Hardware solutions / Routers & switches, VoIP, GSM, etc

Vendor:

Description

The vulnerability allows a remote user to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote administrator on the local network can bypass authentication process and gain unauthorized access to the application.

Mitigation
Install updates from vendor's website.

Vulnerable software versions


External links
http://kb.netgear.com/000062641/Security-Advisory-for-Password-Recovery-Vulnerabilities-on-Some-Rou...


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability