Vulnerability Description
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Cbk40 Firmware | 2.5.0.28 |
| Netgear | Cbk40 | - |
| Netgear | Cbk43 Firmware | 2.5.0.28 |
| Netgear | Cbk43 | - |
| Netgear | Cbr40 Firmware | 2.5.0.28 |
| Netgear | Cbr40 | - |
Related Weaknesses (CWE)
References
- https://github.com/funny-mud-peee/IoT-vuls/blob/main/Netgear%20CBR40%5CCBK40%5CCExploitThird Party Advisory
- https://www.netgear.com/about/security/Vendor Advisory
- https://github.com/funny-mud-peee/IoT-vuls/blob/main/Netgear%20CBR40%5CCBK40%5CCExploitThird Party Advisory
- https://www.netgear.com/about/security/Vendor Advisory
FAQ
What is CVE-2024-28340?
CVE-2024-28340 is a vulnerability with a CVSS score of 7.5 (HIGH). An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authe...
How severe is CVE-2024-28340?
CVE-2024-28340 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28340?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Cbk40 Firmware, Netgear Cbk40, Netgear Cbk43 Firmware, Netgear Cbk43, Netgear Cbr40 Firmware.