A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
2021-12-09T14:15:12.563
2024-11-21T06:26:16.017
Modified
CVSSv3.1: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:P/I:N/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | rax35_firmware | < 1.0.4.102 | Yes |
Hardware | netgear | rax35 | - | No |
Operating System | netgear | rax38_firmware | < 1.0.4.102 | Yes |
Hardware | netgear | rax38 | - | No |
Operating System | netgear | rax40_firmware | < 1.0.4.102 | Yes |
Hardware | netgear | rax40 | - | No |