Vulnerability Description
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | R6700 Firmware | 1.0.4.120 |
| Netgear | R6700 | - |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2021-57Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-57Third Party Advisory
FAQ
What is CVE-2021-23147?
CVE-2021-23147 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a seri...
How severe is CVE-2021-23147?
CVE-2021-23147 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23147?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear R6700 Firmware, Netgear R6700.