PT-2021-6409 · NetGear · Netgear R6220+4

Z3

·

Published

2021-04-29

·

Updated

2022-03-23

·

CVE-2021-44261

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netgear W104 version WAC104-V1.0.4.13 Netgear WAC104 (affected versions not specified) Netgear R7450 (affected versions not specified) Netgear R6900v2 (affected versions not specified) Netgear R7800 (affected versions not specified) Netgear R6220 (affected versions not specified)
Description A vulnerability in the 'BRS top.html' page can allow a remote attacker to access this page without any authentication, exposing firmware version information for the device. The issue is related to deficiencies in the authentication procedure when processing the BRS top.html web page.
Recommendations For Netgear W104 version WAC104-V1.0.4.13, consider restricting access to the BRS top.html page until a patch is available. For Netgear WAC104, R7450, R6900v2, R7800, and R6220, restrict access to the BRS top.html page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01520
CVE-2021-44261

Affected Products

Netgear R6220
Netgear R6900V2
Netgear R7450
Netgear R7800
Netgear Wac104