CVE-2021-23147
MEDIUM WAF: Low
CVSS 6.8
Published: 2021-12-30
CWE-287
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.
WAF Coverage Analysis
Improper Authentication
Low WAF Coverage
OWASP: A07:2021 Identification and Authentication Failures
Affected Software
| Vendor | Product | Version |
|---|---|---|
| netgear | r6700_firmware | 1.0.4.120 |
References
- www.tenable.com (Third Party Advisory)