CVE-2020-27873
Summary
| CVE | CVE-2020-27873 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-04 17:15:00 UTC |
| Updated | 2021-02-08 20:10:00 UTC |
| Description | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SOAP API endpoint, which listens on TCP port 80 by default. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-11559. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Hardware | Netgear | R6020 | - | All | All | All |
| Hardware | Netgear | R6020 | - | All | All | All |
| Operating System | Netgear | R6020 Firmware | All | All | All | All |
| Operating System | Netgear | R6020 Firmware | All | All | All | All |
| Hardware | Netgear | R6080 | - | All | All | All |
| Hardware | Netgear | R6080 | - | All | All | All |
| Operating System | Netgear | R6080 Firmware | All | All | All | All |
| Operating System | Netgear | R6080 Firmware | All | All | All | All |
| Hardware | Netgear | R6120 | - | All | All | All |
| Hardware | Netgear | R6120 | - | All | All | All |
| Operating System | Netgear | R6120 Firmware | All | All | All | All |
| Operating System | Netgear | R6120 Firmware | All | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Hardware | Netgear | R6700 | v2 | All | All | All |
| Hardware | Netgear | R6700 | v2 | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Hardware | Netgear | R6900 | v2 | All | All | All |
| Hardware | Netgear | R6900 | v2 | All | All | All |
| Operating System | Netgear | R6900 Firmware | All | All | All | All |
| Operating System | Netgear | R6900 Firmware | All | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Password Recovery Vulnerabilities on Some Routers | Answer | NETGEAR Support | N/A | kb.netgear.com | Vendor Advisory |
| ZDI-21-072 | Zero Day Initiative | N/A | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.