PT-2021-24295 · NetGear · Netgear Nighthawk R6700

Published

2021-12-30

·

Updated

2022-01-11

·

CVE-2021-45732

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Netgear Nighthawk R6700 version 1.0.4.120
Description: The issue concerns a hardcoded credential in the Netgear Nighthawk R6700. Although configuration backups are encrypted or obfuscated, suggesting they are not intended for user manipulation, an individual can extract the configuration using publicly available tools. This allows for reconfiguring settings that are not meant to be changed, repackaging the configuration, and then restoring the backup to apply these changes.
Recommendations: For Netgear Nighthawk R6700 version 1.0.4.120, consider disabling the ability to restore configuration backups until a patch is available to prevent unauthorized changes to settings. Additionally, restrict access to configuration manipulation tools to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45732

Affected Products

Netgear Nighthawk R6700