Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-34870

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of authentication required for a privileged request. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13325.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 3.3
Products affected by CVE-2021-34870
  • Netgear » Xr1000 » Version: N/A
    cpe:2.3:h:netgear:xr1000:-
  • Netgear » Xr1000 » Version: 1.0.0.52_1.0.38
    cpe:2.3:o:netgear:xr1000:1.0.0.52_1.0.38


Contact Us

Shodan ® - All rights reserved