HIGH · 8.1

CVE-2021-29080

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, ...

Vulnerability Description

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NetgearRbk852 Firmware< 3.2.10.11
NetgearRbk852-
NetgearRbk853 Firmware< 3.2.10.11
NetgearRbk853-
NetgearRbr854 Firmware< 3.2.10.11
NetgearRbr854-
NetgearRbr850 Firmware< 3.2.10.11
NetgearRbr850-
NetgearRbs850 Firmware< 3.2.10.11
NetgearRbs850-
NetgearCbr40 Firmware< 2.5.0.10
NetgearCbr40-
NetgearR7000 Firmware< 1.0.11.116
NetgearR7000-
NetgearR6900P Firmware< 1.3.2.126
NetgearR6900P-
NetgearR7900 Firmware< 1.0.4.38
NetgearR7900-
NetgearR7960P Firmware< 1.4.1.66
NetgearR7960P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-29080?

CVE-2021-29080 is a vulnerability with a CVSS score of 8.1 (HIGH). Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, ...

How severe is CVE-2021-29080?

CVE-2021-29080 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-29080?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Rbk852 Firmware, Netgear Rbk852, Netgear Rbk853 Firmware, Netgear Rbk853, Netgear Rbr854 Firmware.