Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6r85-9phq-3c46

Опубликовано: 14 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper authentication verification before performing a password reset. An attacker can leverage this vulnerability to reset the admin password. Was ZDI-CAN-13483.

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper authentication verification before performing a password reset. An attacker can leverage this vulnerability to reset the admin password. Was ZDI-CAN-13483.

EPSS

Процентиль: 65%
0.00497
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper authentication verification before performing a password reset. An attacker can leverage this vulnerability to reset the admin password. Was ZDI-CAN-13483.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость микропрограммного обеспечения Wi-Fi роутеров NETGEAR D7000v2, R6400, R6400v2, R6700v3, R6900P, R7000, R7000P, R8300, R8500, RS400, XR300, связанная с недостатками процедуры аутентификации перед выполнением сброса пароля, позволяющая нарушителю изменить пароль администратора

EPSS

Процентиль: 65%
0.00497
Низкий

Дефекты

CWE-287