7.5
CVE-2024-28340
- EPSS 0.64%
- Veröffentlicht 12.03.2024 17:15:59
- Zuletzt bearbeitet 27.05.2025 14:23:12
- Erkennungen
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Cbk40 Firmware Version 2.5.0.28
Netgear ≫ Cbk43 Firmware Version 2.5.0.28
Netgear ≫ Cbr40 Firmware Version 2.5.0.28
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.64% | 0.456 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://www.netgear.com/about/security/
https://github.com/funny-mud-peee/IoT-vuls/blob/main/Netgear%20CBR40%5CCBK40%5CCBK43/Info%20Leak%20in%20Netgear-CBR40%E3%80%81CBK40%E3%80%81CBK43%20Router%EF%BC%88currentsetting.htm%EF%BC%89.md