Umbra Wiki cve cve/CVE-2017-5521
Back to wiki

CVE-2017-5521 — NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

provenance: imported · CVE: CVE-2017-5521

CVE-2017-5521: NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project NETGEAR
Product Multiple Devices
Date added 2022-09-08
Due date 2022-09-29
Ransomware campaign use Unknown

Description

Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.

Required action (CISA)

Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.

Notes

https://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability; https://nvd.nist.gov/vuln/detail/CVE-2017-5521

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-5521
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog