CVE-2021-23147

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/12/2021
Last modified:
11/01/2022

Description

Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:r6700_firmware:1.0.4.120:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6700:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools