PT-2021-6409 · NetGear · Netgear R6220+4
Z3
·
Published
2021-04-29
·
Updated
2022-03-23
·
CVE-2021-44261
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netgear W104 version WAC104-V1.0.4.13
Netgear WAC104 (affected versions not specified)
Netgear R7450 (affected versions not specified)
Netgear R6900v2 (affected versions not specified)
Netgear R7800 (affected versions not specified)
Netgear R6220 (affected versions not specified)
Description
A vulnerability in the 'BRS top.html' page can allow a remote attacker to access this page without any authentication, exposing firmware version information for the device. The issue is related to deficiencies in the authentication procedure when processing the BRS top.html web page.
Recommendations
For Netgear W104 version WAC104-V1.0.4.13, consider restricting access to the BRS top.html page until a patch is available.
For Netgear WAC104, R7450, R6900v2, R7800, and R6220, restrict access to the BRS top.html page to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear R6220
Netgear R6900V2
Netgear R7450
Netgear R7800
Netgear Wac104