CVE-2021-45077: High severity netgear r6700 firmware vulnerability
Published Dec 30, 2021
·Updated
Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary configuration file on the device.
Affected Software
4 affected components
Netgear R6700 firmware=1.0.4.120
Netgear R6700
All of the following
Netgear R6700 firmware=1.0.4.120
Netgear R6700
Event History
Dec 30, 2021
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-45077.
2
What is the severity of CVE-2021-45077?
The severity of CVE-2021-45077 is high with a severity value of 7.5.
3
Which Netgear device is affected by CVE-2021-45077?
Netgear Nighthawk R6700 version 1.0.4.120 is affected by CVE-2021-45077.
4
How does CVE-2021-45077 impact the device?
CVE-2021-45077 allows sensitive information, such as usernames and passwords, to be stored in plaintext on the device.
5
Is there a fix for CVE-2021-45077?
Yes, updating to a version of the Netgear Nighthawk R6700 firmware that is not affected by CVE-2021-45077 resolves the issue.