CVE-2021-41449
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD
Description
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
Affected (3)
Products: Netgear: Rax35 Firmware, Rax38 Firmware, Rax40 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.4.102 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax35 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.4.102 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax38 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.4.102 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax40 | All versions |
References (8)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.