CVE-2021-20168

MEDIUM WAF: Low
CVSS 6.8 Published: 2021-12-30
CWE-287

Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user. These default credentials are admin:admin.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
netgearrax43_firmware1.0.3.96

References

Back to CVE Database