NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
CVE-2017-5521는 NETGEAR Multiple Devices에서 확인된 높음 등급 보안 취약점입니다. 공개 데이터에 표시된 영향 버전은 1.0.1.56 1.0.43, 1.0.2.78 1.0.58, 1.0.0.36, 1.0.0.34 10.0.16, 1.0.2.68 60.0.93, 1.0.0.40 1.0.32, 1.0.2.4 9.1.86, 1.0.1.44 1.0.73, 1.0.0.44, 1.0.0.12, 1.0.0.96, 1.0.0.40, 1.0.0.68입니다. CVSS 기본 점수는 8.1점입니다. CISA의 실제 악용 취약점 목록(KEV)에 등록돼 있어 우선 확인이 필요합니다.
CVE-2017-5521는 NETGEAR Multiple Devices에서 확인된 높음 등급 보안 취약점입니다. 공개 데이터에 표시된 영향 버전은 1.0.1.56 1.0.43, 1.0.2.78 1.0.58, 1.0.0.36, 1.0.0.34 10.0.16, 1.0.2.68 60.0.93, 1.0.0.40 1.0.32, 1.0.2.4 9.1.86, 1.0.1.44 1.0.73, 1.0.0.44, 1.0.0.12, 1.0.0.96, 1.0.0.40, 1.0.0.68입니다. CVSS 기본 점수는 8.1점입니다. CISA의 실제 악용 취약점 목록(KEV)에 등록돼 있어 우선 확인이 필요합니다.
NVD 영문 원문의 세부 내용은 한국어 설명으로 순차 보강 중입니다. 보강 전에는 제품·위험도·실제 악용 여부처럼 공개 데이터로 확인된 정보만 표시합니다.
영문 원문 보기
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recover...