CVE-2021-41449
rax35 firmware, rax35
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
- CVSS
- 7.1
- EPSS
- 1.54% 72.6% percentile
- CISA KEV
- Not listed
- Published
- 2021.12.09