Vulnerability Description
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Rbk852 Firmware | < 3.2.10.11 |
| Netgear | Rbk852 | - |
| Netgear | Rbk853 Firmware | < 3.2.10.11 |
| Netgear | Rbk853 | - |
| Netgear | Rbr854 Firmware | < 3.2.10.11 |
| Netgear | Rbr854 | - |
| Netgear | Rbr850 Firmware | < 3.2.10.11 |
| Netgear | Rbr850 | - |
| Netgear | Rbs850 Firmware | < 3.2.10.11 |
| Netgear | Rbs850 | - |
| Netgear | Cbr40 Firmware | < 2.5.0.10 |
| Netgear | Cbr40 | - |
| Netgear | R7000 Firmware | < 1.0.11.116 |
| Netgear | R7000 | - |
| Netgear | R6900P Firmware | < 1.3.2.126 |
| Netgear | R6900P | - |
| Netgear | R7900 Firmware | < 1.0.4.38 |
| Netgear | R7900 | - |
| Netgear | R7960P Firmware | < 1.4.1.66 |
| Netgear | R7960P | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000063007/Security-Advisory-for-Pre-authentication-PasswoVendor Advisory
- https://kb.netgear.com/000063007/Security-Advisory-for-Pre-authentication-PasswoVendor Advisory
FAQ
What is CVE-2021-29080?
CVE-2021-29080 is a vulnerability with a CVSS score of 8.1 (HIGH). Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, ...
How severe is CVE-2021-29080?
CVE-2021-29080 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29080?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Rbk852 Firmware, Netgear Rbk852, Netgear Rbk853 Firmware, Netgear Rbk853, Netgear Rbr854 Firmware.