CVE-2021-23147

Severity
6.8MEDIUM
EPSS
0.0%
top 86.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Latest updateDec 31

Description

Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5netgear_nighthawk_r67001.0.4.120
NVDnetgear/r6700_firmware1.0.4.120

🔴Vulnerability Details

2
GHSA
GHSA-92gj-cjfc-w72m: Netgear Nighthawk R6700 version 12021-12-31
CVEList
CVE-2021-23147: Netgear Nighthawk R6700 version 12021-12-30