Vulnerability identifier: #VU29045
Vulnerability risk: Low
CVSSv4.0: 5.2 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-295
Exploitation vector: Local network
Exploit availability: No
Vulnerable software:
R6700
Hardware solutions /
Routers for home users
Vendor: NETGEAR
Description
The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.
The vulnerability exists due to a missing certification validation within the downloading of files via HTTPS. A remote attacker on the local network can gain access to sensitive information on the target system.
Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versions
R6700: All versions
External links
https://www.zerodayinitiative.com/advisories/ZDI-20-705/
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.