CVE Feed

    Dashboard / CVE / CVE-2020-17409

    CVE-2020-17409

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6260, R6220, R6020, JNR3210, and WNR2020 routers with firmware 1.0.66. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-10754.

    Published:Oct 13, 2020
    Last Modified:Nov 21, 2024
    EPS:Oct 13, 2020
    EPSS Score:0.00299
    CVSS Score:6.5

    Affected Products

    Vendor
    Netgear
    Product
    Jnr3210
    Vendor
    Netgear
    Product
    Jnr3210 Firmware
    Vendor
    Netgear
    Product
    R6020
    Vendor
    Netgear
    Product
    R6020 Firmware
    Vendor
    Netgear
    Product
    R6080
    Vendor
    Netgear
    Product
    R6080 Firmware
    Vendor
    Netgear
    Product
    R6120
    Vendor
    Netgear
    Product
    R6120 Firmware
    Vendor
    Netgear
    Product
    R6220
    Vendor
    Netgear
    Product
    R6220 Firmware
    Vendor
    Netgear
    Product
    R6230
    Vendor
    Netgear
    Product
    R6230 Firmware
    Vendor
    Netgear
    Product
    R6260
    Vendor
    Netgear
    Product
    R6260 Firmware
    Vendor
    Netgear
    Product
    R6330
    Vendor
    Netgear
    Product
    R6330 Firmware
    Vendor
    Netgear
    Product
    R6350
    Vendor
    Netgear
    Product
    R6350 Firmware
    Vendor
    Netgear
    Product
    R6850
    Vendor
    Netgear
    Product
    R6850 Firmware
    Vendor
    Netgear
    Product
    Wnr2020
    Vendor
    Netgear
    Product
    Wnr2020 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High