PT-2021-15393 · NetGear · Netgear Nighthawk R6700

Published

2021-12-30

·

Updated

2022-01-11

·

CVE-2021-23147

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netgear Nighthawk R6700 version 1.0.4.120
Description The issue concerns insufficient protections for the UART console, allowing a malicious actor with physical access to the device to connect to the UART port via a serial connection and execute commands as the root user without authentication.
Recommendations For Netgear Nighthawk R6700 version 1.0.4.120, as a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23147

Affected Products

Netgear Nighthawk R6700