8.1

CVE-2021-29080

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

Data is provided by the National Vulnerability Database (NVD)
NetgearRbk852 Firmware Version < 3.2.10.11
   NetgearRbk852 Version-
NetgearRbk853 Firmware Version < 3.2.10.11
   NetgearRbk853 Version-
NetgearRbr854 Firmware Version < 3.2.10.11
   NetgearRbr854 Version-
NetgearRbr850 Firmware Version < 3.2.10.11
   NetgearRbr850 Version-
NetgearRbs850 Firmware Version < 3.2.10.11
   NetgearRbs850 Version-
NetgearCbr40 Firmware Version < 2.5.0.10
   NetgearCbr40 Version-
NetgearR7000 Firmware Version < 1.0.11.116
   NetgearR7000 Version-
NetgearR6900p Firmware Version < 1.3.2.126
   NetgearR6900p Version-
NetgearR7900 Firmware Version < 1.0.4.38
   NetgearR7900 Version-
NetgearR7960p Firmware Version < 1.4.1.66
   NetgearR7960p Version-
NetgearR8000 Firmware Version < 1.0.4.66
   NetgearR8000 Version-
NetgearR7900p Firmware Version < 1.4.1.66
   NetgearR7900p Version-
NetgearR8000p Firmware Version < 1.4.1.66
   NetgearR8000p Version-
NetgearRax75 Firmware Version < 1.0.3.102
   NetgearRax75 Version-
NetgearRax80 Firmware Version < 1.0.3.102
   NetgearRax80 Version-
NetgearR7000p Firmware Version < 1.3.2.126
   NetgearR7000p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.23
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 4.8 6.5 4.9
AV:A/AC:L/Au:N/C:P/I:P/A:N
cve@mitre.org 8.1 2.8 5.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-640 Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.