PT-2021-24295 · NetGear · Netgear Nighthawk R6700
Published
2021-12-30
·
Updated
2022-01-11
·
CVE-2021-45732
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Netgear Nighthawk R6700 version 1.0.4.120
Description:
The issue concerns a hardcoded credential in the Netgear Nighthawk R6700. Although configuration backups are encrypted or obfuscated, suggesting they are not intended for user manipulation, an individual can extract the configuration using publicly available tools. This allows for reconfiguring settings that are not meant to be changed, repackaging the configuration, and then restoring the backup to apply these changes.
Recommendations:
For Netgear Nighthawk R6700 version 1.0.4.120, consider disabling the ability to restore configuration backups until a patch is available to prevent unauthorized changes to settings. Additionally, restrict access to configuration manipulation tools to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Nighthawk R6700