PT-2020-5396 · NetGear+1 · Netgear Orbi Tri-Band Business Wifi Add-On Satellite+3

Thorsten Schroeder

·

Published

2020-05-18

·

Updated

2020-05-20

·

CVE-2020-11549

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) version 2.5.1.106 NETGEAR Outdoor Satellite (RBS50Y) version 2.5.1.106 NETGEAR Pro Tri-Band Business WiFi Router (SRR60) AC3000 version 2.5.1.106
Description The issue is related to the use of default credentials in the NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite, Pro Tri-Band Business WiFi Router, and Outdoor Satellite devices. This allows an attacker to achieve remote code execution with root privileges on the embedded Linux system by exploiting the default password of the root account, which is the same as the Web-admin component.
Recommendations For NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) version 2.5.1.106, consider changing the default password of the root account and the Web-admin component to prevent exploitation. For NETGEAR Outdoor Satellite (RBS50Y) version 2.5.1.106, consider changing the default password of the root account and the Web-admin component to prevent exploitation. For NETGEAR Pro Tri-Band Business WiFi Router (SRR60) AC3000 version 2.5.1.106, consider changing the default password of the root account and the Web-admin component to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00483
CVE-2020-11549

Affected Products

Linux
Netgear Orbi Tri-Band Business Wifi Add-On Satellite
Netgear Outdoor Satellite
Netgear Pro Tri-Band Business Wifi Router