CVE Feed

    Dashboard / CVE / CVE-2017-5521

    CVE-2017-5521

    An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

    Published:Jan 17, 2017
    Last Modified:Apr 21, 2026
    EPS:Jan 17, 2017
    EPSS Score:0.93804
    CVSS Score:8.1

    CISA Notification

    Description

    An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

    Required Action:

    Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.

    Notes:

    No extra notes provided.

    Due Date
    Sep 29, 2022
    1443 days ago
    Alert Date
    Sep 8, 2022
    1464 days ago

    Affected Products

    Vendor
    Netgear
    Product
    Ac1450
    Vendor
    Netgear
    Product
    Ac1450 Firmware
    Vendor
    Netgear
    Product
    D6220
    Vendor
    Netgear
    Product
    D6220 Firmware
    Vendor
    Netgear
    Product
    D6300
    Vendor
    Netgear
    Product
    D6300 Firmware
    Vendor
    Netgear
    Product
    D6300b
    Vendor
    Netgear
    Product
    D6300b Firmware
    Vendor
    Netgear
    Product
    D6400
    Vendor
    Netgear
    Product
    D6400 Firmware
    Vendor
    Netgear
    Product
    Dgn2200bv4
    Vendor
    Netgear
    Product
    Dgn2200bv4 Firmware
    Vendor
    Netgear
    Product
    R6200
    Vendor
    Netgear
    Product
    R6200 Firmware
    Vendor
    Netgear
    Product
    R6300
    Vendor
    Netgear
    Product
    R6300 Firmware
    Vendor
    Netgear
    Product
    Vegn2610
    Vendor
    Netgear
    Product
    Vegn2610 Firmware
    Vendor
    Netgear
    Product
    Wndr3700v3
    Vendor
    Netgear
    Product
    Wndr3700v3 Firmware
    Vendor
    Netgear
    Product
    Wndr4000
    Vendor
    Netgear
    Product
    Wndr4000 Firmware
    Vendor
    Netgear
    Product
    Wndr4500
    Vendor
    Netgear
    Product
    Wndr4500 Firmware
    Vendor
    Netgear
    Product
    Wnr1000v3
    Vendor
    Netgear
    Product
    Wnr1000v3 Firmware

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High