LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-5521: NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-5521 to its Known Exploited Vulnerabilities catalog on Sep 8, 2022, with a federal patch deadline of Sep 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.

CVE-2017-5521 is an exposure-of-sensitive-information flaw affecting multiple NETGEAR devices. It allows an attacker to obtain the administrator password by sending simple crafted requests to the device’s web management server. Because that password typically grants full control of the appliance, successful abuse can lead to configuration changes, traffic interception, or further network access. Defenders should treat any internet-facing or poorly segmented management interface as high priority until the issue is confirmed remediated.

How it works

The weakness is classified as CWE-200 (Exposure of Sensitive Information). On affected NETGEAR devices the web management server improperly discloses the administrator password in response to specially formed requests. An unauthenticated or low-privilege attacker who can reach the management interface can therefore retrieve credentials that should remain confidential. Once the password is known, the attacker can authenticate as the administrator and perform any action the interface permits. Exact request formats and affected firmware builds are not detailed here; confirm those mechanics against the vendor advisory.

Am I affected? How to find it in your systems

NETGEAR routers, gateways, and similar appliances commonly expose a web-based management interface on HTTP or HTTPS, often bound to the LAN side and sometimes inadvertently reachable from the WAN. Inventory every NETGEAR device on your network by:

Log and telemetry signs of exploitation may include unusual unauthenticated requests to the management URI paths, sudden successful administrator logins from unexpected source addresses, or configuration changes that were not performed by authorized staff. Because the attack can be a single request-response exchange, traditional brute-force indicators may be absent.

How to remediate

Apply the updates supplied by NETGEAR for each affected model, following the vendor’s installation instructions exactly. CISA’s required action is to apply those updates; if a device has reached end-of-life and no update is available, disconnect it from the network if it is still in use. After patching:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently precede broader network compromise. If you have reason to believe the administrator password was obtained, assume the device and any credentials or traffic it handled may have been abused. Rotate all secrets that traversed the device, review downstream systems for lateral movement, and consider running a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNETGEAR · Multiple Devices
WeaknessCWE-200
Added to CISA KEVSep 8, 2022
Federal patch deadlineSep 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities