NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of authentication prior to allowing access to system configuration information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13708.
The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of authentication prior to allowing access to system configuration information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13708.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netgear
Subscribe
|
D6220
Subscribe
D6220 Firmware
Subscribe
D6400
Subscribe
D6400 Firmware
Subscribe
D7000v2
Subscribe
D7000v2 Firmware
Subscribe
Dc112a
Subscribe
Dc112a Firmware
Subscribe
Dgn2200v4
Subscribe
Dgn2200v4 Firmware
Subscribe
Ex3700
Subscribe
Ex3700 Firmware
Subscribe
Ex3800
Subscribe
Ex3800 Firmware
Subscribe
Ex6120
Subscribe
Ex6120 Firmware
Subscribe
Ex6130
Subscribe
Ex6130 Firmware
Subscribe
Ex7000
Subscribe
Ex7000 Firmware
Subscribe
Ex7500
Subscribe
Ex7500 Firmware
Subscribe
Lax20
Subscribe
Lax20 Firmware
Subscribe
Mr60
Subscribe
Mr60 Firmware
Subscribe
Mr80
Subscribe
Mr80 Firmware
Subscribe
Ms60
Subscribe
Ms60 Firmware
Subscribe
Ms80
Subscribe
Ms80 Firmware
Subscribe
R6400
Subscribe
R6400 Firmware
Subscribe
R6400v2
Subscribe
R6400v2 Firmware
Subscribe
R6700v3
Subscribe
R6700v3 Firmware
Subscribe
R6900p
Subscribe
R6900p Firmware
Subscribe
R7000
Subscribe
R7000 Firmware
Subscribe
R7000p
Subscribe
R7000p Firmware
Subscribe
R7100lg
Subscribe
R7100lg Firmware
Subscribe
R7850
Subscribe
R7850 Firmware
Subscribe
R7900p
Subscribe
R7900p Firmware
Subscribe
R7960p
Subscribe
R7960p Firmware
Subscribe
R8000
Subscribe
R8000 Firmware
Subscribe
R8000p
Subscribe
R8000p Firmware
Subscribe
R8300
Subscribe
R8300 Firmware
Subscribe
R8500
Subscribe
R8500 Firmware
Subscribe
Rax15
Subscribe
Rax15 Firmware
Subscribe
Rax20
Subscribe
Rax200
Subscribe
Rax200 Firmware
Subscribe
Rax20 Firmware
Subscribe
Rax35v2
Subscribe
Rax35v2 Firmware
Subscribe
Rax38v2
Subscribe
Rax38v2 Firmware
Subscribe
Rax40v2
Subscribe
Rax40v2 Firmware
Subscribe
Rax42
Subscribe
Rax42 Firmware
Subscribe
Rax43
Subscribe
Rax43 Firmware
Subscribe
Rax45
Subscribe
Rax45 Firmware
Subscribe
Rax48
Subscribe
Rax48 Firmware
Subscribe
Rax50
Subscribe
Rax50 Firmware
Subscribe
Rax50s
Subscribe
Rax50s Firmware
Subscribe
Rax75
Subscribe
Rax75 Firmware
Subscribe
Rax80
Subscribe
Rax80 Firmware
Subscribe
Raxe450
Subscribe
Raxe450 Firmware
Subscribe
Raxe500
Subscribe
Raxe500 Firmware
Subscribe
Rs400
Subscribe
Rs400 Firmware
Subscribe
V6510-1fxaus
Subscribe
V6510-1fxaus Firmware
Subscribe
Wndr3400v3
Subscribe
Wndr3400v3 Firmware
Subscribe
Wnr3500lv2
Subscribe
Wnr3500lv2 Firmware
Subscribe
Xr1000
Subscribe
Xr1000 Firmware
Subscribe
Xr300
Subscribe
Xr300 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21630 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of authentication prior to allowing access to system configuration information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13708. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear
Netgear d6220 Netgear d6220 Firmware Netgear d6400 Netgear d6400 Firmware Netgear d7000v2 Netgear d7000v2 Firmware Netgear dc112a Netgear dc112a Firmware Netgear dgn2200v4 Netgear dgn2200v4 Firmware Netgear ex3700 Netgear ex3700 Firmware Netgear ex3800 Netgear ex3800 Firmware Netgear ex6120 Netgear ex6120 Firmware Netgear ex6130 Netgear ex6130 Firmware Netgear ex7000 Netgear ex7000 Firmware Netgear ex7500 Netgear ex7500 Firmware Netgear lax20 Netgear lax20 Firmware Netgear mr60 Netgear mr60 Firmware Netgear mr80 Netgear mr80 Firmware Netgear ms60 Netgear ms60 Firmware Netgear ms80 Netgear ms80 Firmware Netgear r6400 Netgear r6400 Firmware Netgear r6400v2 Netgear r6400v2 Firmware Netgear r6700v3 Netgear r6700v3 Firmware Netgear r6900p Netgear r6900p Firmware Netgear r7000 Netgear r7000 Firmware Netgear r7000p Netgear r7000p Firmware Netgear r7100lg Netgear r7100lg Firmware Netgear r7850 Netgear r7850 Firmware Netgear r7900p Netgear r7900p Firmware Netgear r7960p Netgear r7960p Firmware Netgear r8000 Netgear r8000 Firmware Netgear r8000p Netgear r8000p Firmware Netgear r8300 Netgear r8300 Firmware Netgear r8500 Netgear r8500 Firmware Netgear rax15 Netgear rax15 Firmware Netgear rax20 Netgear rax200 Netgear rax200 Firmware Netgear rax20 Firmware Netgear rax35v2 Netgear rax35v2 Firmware Netgear rax38v2 Netgear rax38v2 Firmware Netgear rax40v2 Netgear rax40v2 Firmware Netgear rax42 Netgear rax42 Firmware Netgear rax43 Netgear rax43 Firmware Netgear rax45 Netgear rax45 Firmware Netgear rax48 Netgear rax48 Firmware Netgear rax50 Netgear rax50 Firmware Netgear rax50s Netgear rax50s Firmware Netgear rax75 Netgear rax75 Firmware Netgear rax80 Netgear rax80 Firmware Netgear raxe450 Netgear raxe450 Firmware Netgear raxe500 Netgear raxe500 Firmware Netgear rs400 Netgear rs400 Firmware Netgear v6510-1fxaus Netgear v6510-1fxaus Firmware Netgear wndr3400v3 Netgear wndr3400v3 Firmware Netgear wnr3500lv2 Netgear wnr3500lv2 Firmware Netgear xr1000 Netgear xr1000 Firmware Netgear xr300 Netgear xr300 Firmware |
|
| CPEs | cpe:2.3:h:netgear:d6220:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:d6400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:d7000v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:dc112a:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:dgn2200v4:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex3700:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex3800:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex6120:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex6130:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex7000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex7500:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:lax20:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr80:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms80:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700v3:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6900p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7100lg:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7850:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7900p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7960p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8300:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax15:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax200:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax20:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax35v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax38v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax40v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax42:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax43:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax48:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax50s:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax75:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax80:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:raxe450:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:raxe500:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rs400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:v6510-1fxaus:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:wndr3400v3:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:wnr3500lv2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:xr1000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:d6220_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:d6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:d7000v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:dc112a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:dgn2200v4_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex3700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex3800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex6120_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex6130_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex7500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:lax20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr80_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms80_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7100lg_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax15_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax35v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax38v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax40v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax42_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax43_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax48_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax50s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax75_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe450_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rs400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:v6510-1fxaus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:wndr3400v3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:wnr3500lv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:xr1000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:xr300_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear
Netgear d6220 Netgear d6220 Firmware Netgear d6400 Netgear d6400 Firmware Netgear d7000v2 Netgear d7000v2 Firmware Netgear dc112a Netgear dc112a Firmware Netgear dgn2200v4 Netgear dgn2200v4 Firmware Netgear ex3700 Netgear ex3700 Firmware Netgear ex3800 Netgear ex3800 Firmware Netgear ex6120 Netgear ex6120 Firmware Netgear ex6130 Netgear ex6130 Firmware Netgear ex7000 Netgear ex7000 Firmware Netgear ex7500 Netgear ex7500 Firmware Netgear lax20 Netgear lax20 Firmware Netgear mr60 Netgear mr60 Firmware Netgear mr80 Netgear mr80 Firmware Netgear ms60 Netgear ms60 Firmware Netgear ms80 Netgear ms80 Firmware Netgear r6400 Netgear r6400 Firmware Netgear r6400v2 Netgear r6400v2 Firmware Netgear r6700v3 Netgear r6700v3 Firmware Netgear r6900p Netgear r6900p Firmware Netgear r7000 Netgear r7000 Firmware Netgear r7000p Netgear r7000p Firmware Netgear r7100lg Netgear r7100lg Firmware Netgear r7850 Netgear r7850 Firmware Netgear r7900p Netgear r7900p Firmware Netgear r7960p Netgear r7960p Firmware Netgear r8000 Netgear r8000 Firmware Netgear r8000p Netgear r8000p Firmware Netgear r8300 Netgear r8300 Firmware Netgear r8500 Netgear r8500 Firmware Netgear rax15 Netgear rax15 Firmware Netgear rax20 Netgear rax200 Netgear rax200 Firmware Netgear rax20 Firmware Netgear rax35v2 Netgear rax35v2 Firmware Netgear rax38v2 Netgear rax38v2 Firmware Netgear rax40v2 Netgear rax40v2 Firmware Netgear rax42 Netgear rax42 Firmware Netgear rax43 Netgear rax43 Firmware Netgear rax45 Netgear rax45 Firmware Netgear rax48 Netgear rax48 Firmware Netgear rax50 Netgear rax50 Firmware Netgear rax50s Netgear rax50s Firmware Netgear rax75 Netgear rax75 Firmware Netgear rax80 Netgear rax80 Firmware Netgear raxe450 Netgear raxe450 Firmware Netgear raxe500 Netgear raxe500 Firmware Netgear rs400 Netgear rs400 Firmware Netgear v6510-1fxaus Netgear v6510-1fxaus Firmware Netgear wndr3400v3 Netgear wndr3400v3 Firmware Netgear wnr3500lv2 Netgear wnr3500lv2 Firmware Netgear xr1000 Netgear xr1000 Firmware Netgear xr300 Netgear xr300 Firmware |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-08-04T00:26:55.842Z
Reserved: 2021-06-17T19:27:05.662Z
Link: CVE-2021-34983
Updated: 2024-08-04T00:26:55.842Z
Status : Analyzed
Published: 2024-05-07T23:15:13.573
Modified: 2025-08-14T01:40:56.983
Link: CVE-2021-34983
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD