Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a password reset. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netgear
Subscribe
|
D7800
Subscribe
D7800 Firmware
Subscribe
Ex2700
Subscribe
Ex2700 Firmware
Subscribe
Lbr1020
Subscribe
Lbr1020 Firmware
Subscribe
Lbr20
Subscribe
Lbr20 Firmware
Subscribe
R6700ax
Subscribe
R6700ax Firmware
Subscribe
R7800
Subscribe
R7800 Firmware
Subscribe
R8900
Subscribe
R8900 Firmware
Subscribe
R9000
Subscribe
R9000 Firmware
Subscribe
Rax10
Subscribe
Rax10 Firmware
Subscribe
Rax120v1
Subscribe
Rax120v1 Firmware
Subscribe
Rax120v2
Subscribe
Rax120v2 Firmware
Subscribe
Rax70
Subscribe
Rax70 Firmware
Subscribe
Rax78
Subscribe
Rax78 Firmware
Subscribe
Wn3000rpv2
Subscribe
Wn3000rpv2 Firmware
Subscribe
Wn3000rpv3
Subscribe
Wn3000rpv3 Firmware
Subscribe
Xr450
Subscribe
Xr450 Firmware
Subscribe
Xr500
Subscribe
Xr500 Firmware
Subscribe
Xr700
Subscribe
Xr700 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-32369 | Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a password reset. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:47:00.858Z
Reserved: 2021-12-25T00:00:00
Link: CVE-2021-45603
No data.
Status : Modified
Published: 2021-12-26T01:15:17.853
Modified: 2024-11-21T06:32:38.527
Link: CVE-2021-45603
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD