CVE-2021-44261

A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:wac104_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wac104:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:r7450_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7450:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6900:v2:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:*

History

23 Mar 2022, 18:49

Type Values Removed Values Added
References (MISC) https://www.netgear.com/about/security/ - (MISC) https://www.netgear.com/about/security/ - Vendor Advisory
References (MISC) https://github.com/zer0yu/CVE_Request/blob/master/netgear/Netgear_W104_unauthorized_access_vulnerability_first.md - (MISC) https://github.com/zer0yu/CVE_Request/blob/master/netgear/Netgear_W104_unauthorized_access_vulnerability_first.md - Exploit, Third Party Advisory
First Time Netgear r6220
Netgear r6900
Netgear r6220 Firmware
Netgear r7450 Firmware
Netgear r6900 Firmware
Netgear r7800 Firmware
Netgear wac104
Netgear r7450
Netgear
Netgear wac104 Firmware
Netgear r7800
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
CWE CWE-306
CPE cpe:2.3:h:netgear:wac104:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7450_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wac104_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6900:v2:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7450:-:*:*:*:*:*:*:*

17 Mar 2022, 13:39

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-17 13:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-44261

Mitre link : CVE-2021-44261

CVE.ORG link : CVE-2021-44261


JSON object : View

Products Affected

netgear

  • r7450
  • wac104
  • r6220
  • r7800
  • r6900_firmware
  • r6220_firmware
  • wac104_firmware
  • r7800_firmware
  • r6900
  • r7450_firmware
CWE
CWE-306

Missing Authentication for Critical Function