ETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of authentication prior to allowing access to system configuration information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13708.
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
Configuration 16 (hide)
| AND |
|
Configuration 17 (hide)
| AND |
|
Configuration 18 (hide)
| AND |
|
Configuration 19 (hide)
| AND |
|
Configuration 20 (hide)
| AND |
|
Configuration 21 (hide)
| AND |
|
Configuration 22 (hide)
| AND |
|
Configuration 23 (hide)
| AND |
|
Configuration 24 (hide)
| AND |
|
Configuration 25 (hide)
| AND |
|
Configuration 26 (hide)
| AND |
|
Configuration 27 (hide)
| AND |
|
Configuration 28 (hide)
| AND |
|
Configuration 29 (hide)
| AND |
|
Configuration 30 (hide)
| AND |
|
Configuration 31 (hide)
| AND |
|
Configuration 32 (hide)
| AND |
|
Configuration 33 (hide)
| AND |
|
Configuration 34 (hide)
| AND |
|
Configuration 35 (hide)
| AND |
|
Configuration 36 (hide)
| AND |
|
Configuration 37 (hide)
| AND |
|
Configuration 38 (hide)
| AND |
|
Configuration 39 (hide)
| AND |
|
Configuration 40 (hide)
| AND |
|
Configuration 41 (hide)
| AND |
|
Configuration 42 (hide)
| AND |
|
Configuration 43 (hide)
| AND |
|
Configuration 44 (hide)
| AND |
|
Configuration 45 (hide)
| AND |
|
Configuration 46 (hide)
| AND |
|
Configuration 47 (hide)
| AND |
|
Configuration 48 (hide)
| AND |
|
Configuration 49 (hide)
| AND |
|
Configuration 50 (hide)
| AND |
|
Configuration 51 (hide)
| AND |
|
Configuration 52 (hide)
| AND |
|
14 Aug 2025, 01:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kb.netgear.com/000064313/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Extenders-Routers-and-DSL-Modem-Routers-PSV-2021-0159 - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1275/ - Third Party Advisory | |
| First Time |
Netgear ex3700
Netgear dgn2200v4 Firmware Netgear r7000 Firmware Netgear rax15 Firmware Netgear r7900p Firmware Netgear r7000p Netgear raxe450 Netgear wnr3500lv2 Firmware Netgear ex7500 Firmware Netgear rax20 Netgear mr80 Firmware Netgear ex6130 Firmware Netgear xr1000 Netgear r6700v3 Netgear d6400 Firmware Netgear r6700v3 Firmware Netgear rax38v2 Netgear dgn2200v4 Netgear ex3800 Firmware Netgear mr60 Netgear ms60 Netgear rax38v2 Firmware Netgear d6220 Firmware Netgear rax45 Netgear r7100lg Firmware Netgear rax35v2 Netgear r8500 Firmware Netgear rax42 Firmware Netgear ex7000 Netgear r8000 Netgear ms60 Firmware Netgear r7100lg Netgear r6400v2 Firmware Netgear ex7000 Firmware Netgear rax75 Netgear ex6120 Firmware Netgear rax42 Netgear r8500 Netgear lax20 Firmware Netgear xr1000 Firmware Netgear wnr3500lv2 Netgear rax75 Firmware Netgear rax50 Netgear rax50s Firmware Netgear ex3800 Netgear rax20 Firmware Netgear v6510-1fxaus Netgear wndr3400v3 Netgear rax15 Netgear r7850 Netgear rax50 Firmware Netgear dc112a Firmware Netgear ex6130 Netgear xr300 Netgear r8000p Firmware Netgear r8000p Netgear d7000v2 Firmware Netgear raxe500 Netgear d7000v2 Netgear ms80 Netgear lax20 Netgear rax200 Netgear ex6120 Netgear rax40v2 Firmware Netgear rax50s Netgear rax48 Firmware Netgear r8300 Netgear rax200 Firmware Netgear wndr3400v3 Firmware Netgear r6400 Firmware Netgear r7000 Netgear r6400 Netgear rax43 Firmware Netgear r6900p Firmware Netgear ex7500 Netgear ms80 Firmware Netgear r7000p Firmware Netgear r6400v2 Netgear xr300 Firmware Netgear r7960p Firmware Netgear r6900p Netgear Netgear r7850 Firmware Netgear rs400 Firmware Netgear rax48 Netgear rax35v2 Firmware Netgear rax43 Netgear raxe450 Firmware Netgear raxe500 Firmware Netgear mr80 Netgear rax80 Firmware Netgear r7960p Netgear dc112a Netgear r8000 Firmware Netgear r7900p Netgear rax40v2 Netgear d6220 Netgear v6510-1fxaus Firmware Netgear rax45 Firmware Netgear d6400 Netgear r8300 Firmware Netgear mr60 Firmware Netgear ex3700 Firmware Netgear rs400 Netgear rax80 |
|
| CPE | cpe:2.3:o:netgear:r7850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rs400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms80:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:d7000v2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex6130_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:v6510-1fxaus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:dc112a:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax80:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax35v2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:xr1000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax20:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex6130:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax43_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax15_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms80_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax75:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7960p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex7500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:wndr3400v3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:xr1000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax42_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax48_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:raxe450:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:dgn2200v4_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe450_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:d6400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8500_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7100lg:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:v6510-1fxaus:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8300:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:d6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex3800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rs400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax75_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax40v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:raxe500:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax50s:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7100lg_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:lax20:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:dgn2200v4:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex3800:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax15:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700v3:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax48:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax50s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex3700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax38v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr80:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:d7000v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:wndr3400v3:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex6120:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:dc112a_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:wnr3500lv2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax200:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex7000:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7900p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:d6220_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax38v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax42:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:xr300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:lax20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:wnr3500lv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex3700:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax43:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax40v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex6120_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6900p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:d6220:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax35v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex7500:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr80_firmware:*:*:*:*:*:*:*:* |
21 Nov 2024, 06:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kb.netgear.com/000064313/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Extenders-Routers-and-DSL-Modem-Routers-PSV-2021-0159 - | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1275/ - |
04 Aug 2024, 01:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
03 Jul 2024, 01:36
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-120 |
08 May 2024, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-05-07 23:15
Updated : 2025-08-14 01:40
NVD link : CVE-2021-34983
Mitre link : CVE-2021-34983
CVE.ORG link : CVE-2021-34983
JSON object : View
- r8300_firmware
- ex7500
- r6400
- r8500
- rax42
- xr300_firmware
- r8000p_firmware
- r7100lg
- ex6120_firmware
- rax15
- d6400_firmware
- d6220
- rax80
- rax45
- rax75_firmware
- r7960p_firmware
- raxe450_firmware
- rax35v2
- rax200
- rax50s_firmware
- rax40v2
- rs400_firmware
- ex3800
- r8500_firmware
- rax20_firmware
- rax75
- rax43_firmware
- mr60_firmware
- raxe500_firmware
- d6400
- rax48
- ex7500_firmware
- ms60
- wnr3500lv2
- raxe450
- ex6130_firmware
- ex3700_firmware
- rax38v2_firmware
- rax43
- ex7000_firmware
- xr1000_firmware
- r7850_firmware
- r8000p
- rax45_firmware
- mr80
- rax20
- r7850
- ex3800_firmware
- v6510-1fxaus_firmware
- r6900p_firmware
- r7000
- rax50s
- rax80_firmware
- r7900p_firmware
- d6220_firmware
- rax50_firmware
- r7960p
- rax40v2_firmware
- mr60
- r6700v3_firmware
- r6700v3
- wnr3500lv2_firmware
- rax48_firmware
- r8000
- ex7000
- dgn2200v4_firmware
- ms60_firmware
- dc112a_firmware
- ex6130
- r6400_firmware
- v6510-1fxaus
- ms80_firmware
- lax20
- lax20_firmware
- rax200_firmware
- r6400v2
- wndr3400v3_firmware
- dc112a
- ex3700
- r8000_firmware
- rax42_firmware
- r7000p
- r7100lg_firmware
- dgn2200v4
- xr300
- rax15_firmware
- r7900p
- xr1000
- d7000v2
- rax35v2_firmware
- r6900p
- rax50
- ms80
- rax38v2
- r7000p_firmware
- rs400
- raxe500
- r7000_firmware
- r8300
- mr80_firmware
- d7000v2_firmware
- wndr3400v3
- r6400v2_firmware
- ex6120
Missing Authentication for Critical Function