← All CVEs

CVE-2017-5521

high · 8.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.

Added 2022-09-08Remediation due 2022-09-29

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

8.1
CVSS
89.2%
EPSS (exploit prob.)
100th
EPSS percentile
2017-01-17
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
netgearr6200_firmware1.0.1.56_1.0.43
netgearr6200all versions
netgearr6300_firmware1.0.2.78_1.0.58
netgearr6300all versions
netgearvegn2610_firmware1.0.0.36
netgearvegn2610all versions
netgearac1450_firmware1.0.0.34_10.0.16
netgearac1450all versions
netgearwnr1000v3_firmware1.0.2.68_60.0.93
netgearwnr1000v3all versions
netgearwndr3700v3_firmware1.0.0.40_1.0.32
netgearwndr3700v3all versions
netgearwndr4000_firmware1.0.2.4_9.1.86
netgearwndr4000all versions
netgearwndr4500_firmware1.0.1.44_1.0.73
netgearwndr4500all versions
netgeard6400_firmware1.0.0.44
netgeard6400all versions
netgeard6220_firmware1.0.0.12
netgeard6220all versions
netgeard6300_firmware1.0.0.96
netgeard6300all versions
netgeard6300b_firmware1.0.0.40
netgeard6300ball versions
netgeardgn2200bv4_firmware1.0.0.68
netgeardgn2200bv4all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-5521