An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
2024-03-12T17:15:59.140
2025-05-27T14:23:12.727
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | cbk40_firmware | 2.5.0.28 | Yes |
Hardware | netgear | cbk40 | - | No |
Operating System | netgear | cbk43_firmware | 2.5.0.28 | Yes |
Hardware | netgear | cbk43 | - | No |
Operating System | netgear | cbr40_firmware | 2.5.0.28 | Yes |
Hardware | netgear | cbr40 | - | No |