A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NNetgear Mbr1517
HWNetgearv2Netgear Mbr1517 Firmware
OSNetgearwszystkie wersjeNetgear Wac104
HWNetgearwszystkie wersjeNetgear Wac104 Firmware
OSNetgear≤ 1.0.4.13Netgear Wnce3001
HWNetgearwszystkie wersjeNetgear Wnce3001 Firmware
OSNetgearwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2021-35973CRITICAL9.8PL ✓ten sam produkt
Authentication bypass w NETGEAR WAC104 umożliwiający przejęcie urządzenia
CVE-2020-35788HIGH7.6ten sam produkt
NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.
CVE-2021-44261MEDIUM5.3ten sam produkt
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a...
CVE-2021-38532MEDIUM6.8ten sam produkt
NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.
CVE-2020-26919CRITICAL9.8⚠ KEVPL ✓ten sam vendor
Brak kontroli dostępu na poziomie funkcji w NETGEAR JGS516PE