Lucene search

K
cveZdiCVE-2020-17409
HistoryOct 13, 2020 - 5:15 p.m.

CVE-2020-17409

2020-10-1317:15:13
CWE-288
zdi
web.nvd.nist.gov
38
cve-2020-17409
netgear
routers
vulnerability
information disclosure
mini_httpd
authentication bypass
security

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.002

Percentile

58.9%

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6260, R6220, R6020, JNR3210, and WNR2020 routers with firmware 1.0.66. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-10754.

Affected configurations

Nvd
Vulners
Node
netgearr6020Match-
AND
netgearr6020_firmwareRange<1.0.0.44
Node
netgearr6080Match-
AND
netgearr6080_firmwareRange<1.0.0.44
Node
netgearr6120Match-
AND
netgearr6120_firmwareRange<1.0.0.70
Node
netgearr6220Match-
AND
netgearr6220_firmwareRange<1.1.0.100
Node
netgearr6230Match-
AND
netgearr6230_firmwareRange<1.1.0.100
Node
netgearr6260Match-
AND
netgearr6260_firmwareRange<1.1.0.76
Node
netgearr6330Match-
AND
netgearr6330_firmwareRange<1.1.0.76
Node
netgearr6350Match-
AND
netgearr6350_firmwareRange<1.1.0.76
Node
netgearr6850_firmwareRange<1.1.0.76
AND
netgearr6850Match-
Node
netgearjnr3210_firmwareMatch-
AND
netgearjnr3210Match-
Node
netgearwnr2020_firmwareMatch-
AND
netgearwnr2020Match-
VendorProductVersionCPE
netgearr6020-cpe:2.3:h:netgear:r6020:-:*:*:*:*:*:*:*
netgearr6020_firmware*cpe:2.3:o:netgear:r6020_firmware:*:*:*:*:*:*:*:*
netgearr6080-cpe:2.3:h:netgear:r6080:-:*:*:*:*:*:*:*
netgearr6080_firmware*cpe:2.3:o:netgear:r6080_firmware:*:*:*:*:*:*:*:*
netgearr6120-cpe:2.3:h:netgear:r6120:-:*:*:*:*:*:*:*
netgearr6120_firmware*cpe:2.3:o:netgear:r6120_firmware:*:*:*:*:*:*:*:*
netgearr6220-cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:*
netgearr6220_firmware*cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:*
netgearr6230-cpe:2.3:h:netgear:r6230:-:*:*:*:*:*:*:*
netgearr6230_firmware*cpe:2.3:o:netgear:r6230_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 221

CNA Affected

[
  {
    "product": "Multiple Routers",
    "vendor": "NETGEAR",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.66"
      }
    ]
  }
]

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.002

Percentile

58.9%

Related for CVE-2020-17409