CVE-2021-45493: Infoleak
Published Dec 26, 2021
·Updated
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.
Affected Software
12 affected components
All of the following
Netgear Rax35 Firmware<1.0.4.102
Netgear RAX35
All of the following
Netgear Rax38 Firmware<1.0.4.102
Netgear RAX38
All of the following
Netgear Rax40 Firmware<1.0.4.102
Netgear RAX40
Netgear Rax35 Firmware<1.0.4.102
Netgear RAX35
Netgear Rax38 Firmware<1.0.4.102
Netgear RAX38
Netgear Rax40 Firmware<1.0.4.102
Netgear RAX40
Event History
Dec 26, 2021
CVE Published
via MITRE·01:04 AM
Data Sourced
via MITRE·01:04 AM
DescriptionSeverity
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which NETGEAR devices are affected by CVE-2021-45493?
RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102 are affected by CVE-2021-45493.
2
What is the severity of CVE-2021-45493?
CVE-2021-45493 has a severity of 7.5 (high).
3
How can I fix CVE-2021-45493?
To fix CVE-2021-45493, update your NETGEAR device firmware to version 1.0.4.102 or higher.
4
Where can I find more information about CVE-2021-45493?
You can find more information about CVE-2021-45493 in the NETGEAR security advisory at https://kb.netgear.com/000064453/Security-Advisory-for-Admin-Credential-Disclosure-on-Some-Routers-PSV-2019-0293.
5
What is the CWE ID for CVE-2021-45493?
The CWE ID for CVE-2021-45493 is 200.