peter bassill · operator
$ cve CVE-2017-5521 JSON

CVE-2017-5521 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 89.2% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-29.

Description

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS89.25% — more likely to be exploited than 100% of all CVEs
On CISA KEVyes — remediate by 2022-09-29
Public exploityes
Published2017-01-17
Last modified2026-06-17

CISA KEV

NameNETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
Added2022-09-08
Due2022-09-29
Vendor / productNETGEAR / Multiple Devices
Ransomware usenone reported

Affected (26)

VendorProduct
netgearac1450
netgearac1450 firmware
netgeard6220
netgeard6220 firmware
netgeard6300
netgeard6300 firmware
netgeard6300b
netgeard6300b firmware
netgeard6400
netgeard6400 firmware
netgeardgn2200bv4
netgeardgn2200bv4 firmware
netgearr6200
netgearr6200 firmware
netgearr6300
netgearr6300 firmware
netgearvegn2610
netgearvegn2610 firmware
netgearwndr3700v3
netgearwndr3700v3 firmware
netgearwndr4000
netgearwndr4000 firmware
netgearwndr4500
netgearwndr4500 firmware
netgearwnr1000v3
netgearwnr1000v3 firmware

Public exploits

SourceTitleDate
exploit-dbNetgear Routers - Password Disclosure2017-01-30

References

→ the Explorer  ·  watch your stack  ·  NVD