CVE-2021-20168: High severity netgear rax43 vulnerability
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user. These default credentials are admin:admin.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the Netgear RAX43?
The vulnerability ID of the Netgear RAX43 is CVE-2021-20168.
What is the severity of CVE-2021-20168?
The severity of CVE-2021-20168 is high, with a severity value of 6.8.
What software versions of Netgear RAX43 are affected by CVE-2021-20168?
Netgear RAX43 version 1.0.3.96 is affected by CVE-2021-20168.
How can a malicious actor exploit CVE-2021-20168?
A malicious actor with physical access to the device can connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user.
Is Netgear RAX43 version 1.0.3.96 vulnerable to CVE-2021-20168?
Yes, Netgear RAX43 version 1.0.3.96 is vulnerable to CVE-2021-20168.