CVE-2021-34983
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of authentication prior to allowing access to system configuration information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13708.
Falta autenticación httpd de varios enrutadores de NETGEAR para vulnerabilidad de divulgación de información de funciones críticas. Esta vulnerabilidad permite a atacantes adyacentes a la red revelar información confidencial sobre instalaciones afectadas de múltiples enrutadores NETGEAR. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe dentro del servicio httpd, que escucha en el puerto TCP 80 de forma predeterminada. El problema se debe a la falta de autenticación antes de permitir el acceso a la información de configuración del sistema. Un atacante puede aprovechar esta vulnerabilidad para revelar las credenciales almacenadas, lo que provocaría un mayor compromiso. Era ZDI-CAN-13708.
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of authentication prior to allowing access to system configuration information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-06-17 CVE Reserved
- 2021-10-29 CVE Published
- 2024-08-04 CVE Updated
- 2025-08-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-21-1275 | X_research Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | D6220 Firmware Search vendor "Netgear" for product "D6220 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | D6400 Firmware Search vendor "Netgear" for product "D6400 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | D7000v2 Firmware Search vendor "Netgear" for product "D7000v2 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Dc112a Firmware Search vendor "Netgear" for product "Dc112a Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Dgn2200v4 Firmware Search vendor "Netgear" for product "Dgn2200v4 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ex3700 Firmware Search vendor "Netgear" for product "Ex3700 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ex3800 Firmware Search vendor "Netgear" for product "Ex3800 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ex6120 Firmware Search vendor "Netgear" for product "Ex6120 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ex6130 Firmware Search vendor "Netgear" for product "Ex6130 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ex7000 Firmware Search vendor "Netgear" for product "Ex7000 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ex7500 Firmware Search vendor "Netgear" for product "Ex7500 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Lax20 Firmware Search vendor "Netgear" for product "Lax20 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Mr60 Firmware Search vendor "Netgear" for product "Mr60 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Mr80 Firmware Search vendor "Netgear" for product "Mr80 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ms60 Firmware Search vendor "Netgear" for product "Ms60 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Ms80 Firmware Search vendor "Netgear" for product "Ms80 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R6400 Firmware Search vendor "Netgear" for product "R6400 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R6400v2 Firmware Search vendor "Netgear" for product "R6400v2 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R6700v3 Firmware Search vendor "Netgear" for product "R6700v3 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R6900p Firmware Search vendor "Netgear" for product "R6900p Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R7000 Firmware Search vendor "Netgear" for product "R7000 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R7000p Firmware Search vendor "Netgear" for product "R7000p Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R7100lg Firmware Search vendor "Netgear" for product "R7100lg Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R7850 Firmware Search vendor "Netgear" for product "R7850 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R7900p Firmware Search vendor "Netgear" for product "R7900p Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R7960p Firmware Search vendor "Netgear" for product "R7960p Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R8000 Firmware Search vendor "Netgear" for product "R8000 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R8000p Firmware Search vendor "Netgear" for product "R8000p Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R8300 Firmware Search vendor "Netgear" for product "R8300 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | R8500 Firmware Search vendor "Netgear" for product "R8500 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax15 Firmware Search vendor "Netgear" for product "Rax15 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax200 Firmware Search vendor "Netgear" for product "Rax200 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax20 Firmware Search vendor "Netgear" for product "Rax20 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax35v2 Firmware Search vendor "Netgear" for product "Rax35v2 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax38v2 Firmware Search vendor "Netgear" for product "Rax38v2 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax40v2 Firmware Search vendor "Netgear" for product "Rax40v2 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax42 Firmware Search vendor "Netgear" for product "Rax42 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax43 Firmware Search vendor "Netgear" for product "Rax43 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax45 Firmware Search vendor "Netgear" for product "Rax45 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax48 Firmware Search vendor "Netgear" for product "Rax48 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax50 Firmware Search vendor "Netgear" for product "Rax50 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax50s Firmware Search vendor "Netgear" for product "Rax50s Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax75 Firmware Search vendor "Netgear" for product "Rax75 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rax80 Firmware Search vendor "Netgear" for product "Rax80 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Raxe450 Firmware Search vendor "Netgear" for product "Raxe450 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Raxe500 Firmware Search vendor "Netgear" for product "Raxe500 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Rs400 Firmware Search vendor "Netgear" for product "Rs400 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | V6510-1fxaus Firmware Search vendor "Netgear" for product "V6510-1fxaus Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Wndr3400v3 Firmware Search vendor "Netgear" for product "Wndr3400v3 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Wnr3500lv2 Firmware Search vendor "Netgear" for product "Wnr3500lv2 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Xr1000 Firmware Search vendor "Netgear" for product "Xr1000 Firmware" | * | - |
Affected
| ||||||
Netgear Search vendor "Netgear" | Xr300 Firmware Search vendor "Netgear" for product "Xr300 Firmware" | * | - |
Affected
|