Impact
Insufficient configuration management allows authenticated administrators connected to the local network to tamper with the system. This can enable changes to any available configuration settings, affecting routing, firewall rules, or other operational parameters. The weakness involves improper configuration controls (CWE‑15) and inadequate authorization handling (CWE‑610).
Affected Systems
The vulnerability affects a substantial portion of NETGEAR routers, access points, and Wi‑Fi solutions, including the CBR750, EX6120, EX6130, MR60, MR70, MR80, MS60, MS70, MS80, RAX15, RAX20, RAX200, RAX35v2, RAX38v2, RAX40v2, RAX42, RAX43, RAX45, RAX48, RAX50, RAX50S, RAX75, RAX80, RAXE450, RAXE500, RBR750, RBR840, RBR850, RBRE960, RBS750, RBS840, RBS850, RBSE960, RS700, and XR1000.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the vulnerability is not listed in CISA KEV. The EPSS score of < 1% indicates a very low probability of exploitation. The likely attack vector is local, requiring authenticated administrator access over the local network. Once compromised, an attacker could modify device configuration to disrupt services or weaken security controls, but the impact is limited to the scope of devices still in operation. Patching is the most effective mitigation.
OpenCVE Enrichment