First published: Tue Mar 12 2024(Updated: )
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear CBR40 | ||
Netgear CBK40 | ||
Netgear Orbi RBK43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28340 is rated as a high-severity vulnerability due to its ability to expose sensitive information without authentication.
To mitigate CVE-2024-28340, users should immediately update their Netgear CBR40, CBK40, and CBK43 devices to the latest firmware version provided by Netgear.
CVE-2024-28340 allows attackers to obtain sensitive information, although specific details of the leaked information depend on the device configuration.
No, CVE-2024-28340 can be exploited without any authentication, making it particularly dangerous.
CVE-2024-28340 affects the Netgear CBR40, CBK40, and CBK43 models running version 2.5.0.28.