The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp HTML source code.
2016-06-20T01:59:01.133
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | d3600_firmware | 1.0.0.49 | Yes |
Hardware | netgear | d3600 | - | No |
Operating System | netgear | d6000_firmware | ≤ 1.0.0.49 | Yes |
Hardware | netgear | d6000 | - | No |