6.1

CVE-2021-45603

Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a password reset. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46.

Data is provided by the National Vulnerability Database (NVD)
NetgearD7800 Firmware Version < 1.0.1.66
   NetgearD7800 Version-
NetgearEx2700 Firmware Version < 1.0.1.68
   NetgearEx2700 Version-
NetgearWn3000rpv2 Firmware Version < 1.0.0.90
   NetgearWn3000rpv2 Version-
NetgearWn3000rpv3 Firmware Version < 1.0.2.100
   NetgearWn3000rpv3 Version-
NetgearLbr1020 Firmware Version < 2.6.5.20
   NetgearLbr1020 Version-
NetgearLbr20 Firmware Version < 2.6.5.32
   NetgearLbr20 Version-
NetgearR6700ax Firmware Version < 1.0.10.110
   NetgearR6700ax Version-
NetgearR7800 Firmware Version < 1.0.2.86
   NetgearR7800 Version-
NetgearR8900 Firmware Version < 1.0.5.38
   NetgearR8900 Version-
NetgearR9000 Firmware Version < 1.0.5.38
   NetgearR9000 Version-
NetgearRax10 Firmware Version < 1.0.10.110
   NetgearRax10 Version-
NetgearRax120v1 Firmware Version < 1.2.3.28
   NetgearRax120v1 Version-
NetgearRax120v2 Firmware Version < 1.2.3.28
   NetgearRax120v2 Version-
NetgearRax70 Firmware Version < 1.0.10.110
   NetgearRax70 Version-
NetgearRax78 Firmware Version < 1.0.10.110
   NetgearRax78 Version-
NetgearXr450 Firmware Version < 2.3.2.130
   NetgearXr450 Version-
NetgearXr500 Firmware Version < 2.3.2.130
   NetgearXr500 Version-
NetgearXr700 Firmware Version < 1.0.1.46
   NetgearXr700 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.029
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
cve@mitre.org 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.