CRITICAL🇵🇱 Wersja polska

CVE-2025-4978

CVSS 9.3v4.0pub. 2025-05-20upd. 2025-06-12

A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.

🤖 AI Analysis
How it works

The vulnerability is due to improper authentication implementation (CWE-287) in the component handling the /BRS_top.html file. This resource is accessible without required authentication, allowing an attacker to bypass the Basic Authentication mechanism. The attack can be conducted remotely over the network, without user interaction and without any prior privileges. The exploit has been made public and may be actively exploited.

Impact

An attacker can gain unauthorized access to protected device resources, threatening the confidentiality, integrity, and availability of the system. This could lead to takeover of the router and modification of its configuration.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. It is recommended to monitor official Netgear security communications at https://www.netgear.com/. Until a patch is released, it is recommended to restrict access to the device management interface through a firewall or network segmentation.

Who is affected

Netgear DGND3700 with firmware version 1.1.00.15_1.00.15NA. According to manufacturer information, other Netgear products may also be affected.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Netgear Dgnd3700

    HW
    Netgear
    v2
  • Netgear Dgnd3700 Firmware

    OS
    Netgear
    1.1.00.15_1.00.15na
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2019-17373CRITICAL9.8PL ✓same product

Ominięcie uwierzytelnienia w urządzeniach NETGEAR via manipulacja URL

CVE-2016-5649CRITICAL9.8PL ✓same product

Netgear DGN2200/DGND3700 — ujawnienie hasła admina w postaci jawnego tekstu

CVE-2016-11059HIGH7.5same product

Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before...

CVE-2025-4977MEDIUM6.9same product

A vulnerability, which was classified as problematic, has been found in Netgear DGND3700 1.1.00.15_1.00.15NA. ...

CVE-2025-4980MEDIUM6.9same product

A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vul...