Vulnerability identifier: #VU77789
Vulnerability risk: Low
CVSSv4.0: 4.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-16
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
MK82
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MR80
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MS80
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBRE960
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBSE960
Hardware solutions /
Routers & switches, VoIP, GSM, etc
C7000v2
Hardware solutions /
Routers & switches, VoIP, GSM, etc
CBR750
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MR70
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MS70
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX42
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX43
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX48
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX45
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX50
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX50S
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX38v2
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX35v2
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAX40v2
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAXE500
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RAXE450
Hardware solutions /
Routers & switches, VoIP, GSM, etc
R6700v3
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBK752
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBR750
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBS750
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBK852
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBR850
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBS850
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBK842
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBR840
Hardware solutions /
Routers & switches, VoIP, GSM, etc
RBS840
Hardware solutions /
Routers & switches, VoIP, GSM, etc
CAX80
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MK62
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MR60
Hardware solutions /
Routers & switches, VoIP, GSM, etc
MS60
Hardware solutions /
Routers & switches, VoIP, GSM, etc
Vendor: NETGEAR
Description
The issue may allow a local attacker to bypass implemented security restrictions.
The issue exists due to the possibility to a security misconfiguration issue. A local attacker can gain access to sensitive information on the system.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
MK82: before 1.1.7.12
MR80: before 1.1.7.12
MS80: before 1.1.7.12
RBRE960: before 6.3.7.5
RBSE960: before 6.3.7.5
C7000v2: before 1.03.08
CBR750: before 4.6.14.4
MR70: before 1.0.2.26
MS70: before 1.0.2.26
RAX42: before 1.0.11.112
RAX43: before 1.0.11.112
RAX48: before 1.0.11.112
RAX45: before 1.0.11.112
RAX50: before 1.0.11.112
RAX50S: before 1.0.11.112
RAX38v2: before 1.0.11.112
RAX35v2: before 1.0.11.112
RAX40v2: before 1.0.11.112
RAXE500: before 1.0.10.86
RAXE450: before 1.0.10.86
R6700v3: before 1.0.4.128
RBK752: before 4.6.9.11
RBR750: before 4.6.9.11
RBS750: before 4.6.9.11
RBK852: before 4.6.9.11
RBR850: before 4.6.9.11
RBS850: before 4.6.9.11
RBK842: before 4.6.9.11
RBR840: before 4.6.9.11
RBS840: before 4.6.9.11
CAX80: before 2.1.4.2
MK62: before 1.1.7.132
MR60: before 1.1.7.132
MS60: before 1.1.7.132
External links
https://kb.netgear.com/000065713/Security-Advisory-for-Security-Misconfiguration-on-Some-Routers-and-WiFi-Systems-PSV-2022-0010
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.