Junglewise Threat Intelligence

CVE-2017-5521: NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

CVE-2017-5521 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2022-09-08

Technologies: NETGEAR R7000, Geovision Multiple Devices. Vendors: NETGEAR, Geovision.

Executive brief

Multiple NETGEAR routers are vulnerable to admin password disclosure when password recovery is not enabled. An attacker can obtain a recovery token by canceling authentication and then use that token via a crafted request to /passwordrecovered.cgi to retrieve the administrator password.

Affected products

  • NETGEAR R8500
  • NETGEAR R8300
  • NETGEAR R7000
  • NETGEAR R6400
  • NETGEAR R7300
  • NETGEAR R7100LG
  • NETGEAR R6300v2
  • NETGEAR WNDR3400v3
  • NETGEAR WNR3500Lv2
  • NETGEAR R6250
  • NETGEAR R6700
  • NETGEAR R6900
  • NETGEAR R8000

Timeline

  • 2017-01-19: disclosed: SecurityFocus BID 95457 published
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats