CVE-2021-41449: Path Traversal
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netgear RAX35/RAX38/RAX40to a version that resolves this vulnerability.Fixed in v1.0.4.102
Event History
Frequently Asked Questions
What is the vulnerability ID of this path traversal attack?
The vulnerability ID of this path traversal attack is CVE-2021-41449.
What routers are affected by this path traversal vulnerability?
The Netgear RAX35, RAX38, and RAX40 routers are affected by this path traversal vulnerability.
What is the severity of CVE-2021-41449?
The severity of CVE-2021-41449 is high with a CVSS score of 7.1.
How can a remote unauthenticated attacker exploit this vulnerability?
A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP packet to gain access to sensitive restricted information.
What is the recommended solution for this vulnerability?
It is recommended to update the firmware of the affected routers to version 1.0.4.102 or newer to mitigate this vulnerability.