CVE-2021-20168
MEDIUM WAF: Low
CVSS 6.8
Published: 2021-12-30
CWE-287
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user. These default credentials are admin:admin.
WAF Coverage Analysis
Improper Authentication
Low WAF Coverage
OWASP: A07:2021 Identification and Authentication Failures
Affected Software
| Vendor | Product | Version |
|---|---|---|
| netgear | rax43_firmware | 1.0.3.96 |
References
- www.tenable.com (Third Party Advisory)