Security News > 2021 > December > Netgear leaves vulnerabilities unpatched in Nighthawk router

Netgear leaves vulnerabilities unpatched in Nighthawk router
2021-12-31 12:15

Researchers have found half a dozen high-risk vulnerabilities in the latest firmware version for the Netgear Nighthawk R6700v3 router.

Nighthawk R6700 is a popular dual-bank WiFi router advertised with gaming-focused features, smart parental controls, and internal hardware that is sufficiently powerful to accommodate the needs of home power users.

CVE-2021-20174: HTTP is used by default on all communications of the device's web interface, risking username and password interception in cleartext form.

On top of the aforementioned security issues, Tenable found several instances of jQuery libraries relying on version 1.4.2, which is known to contain vulnerabilities.

The recently disclosed flaws affect firmware version 1.0.4.120, which is the latest release for the device.

The current security report refers to Netgear R6700 v3, which is still under support, not Netgear R6700 v1 and R6700 v2, which have reached end of life.


News URL

https://www.bleepingcomputer.com/news/security/netgear-leaves-vulnerabilities-unpatched-in-nighthawk-router/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-12-30 CVE-2021-20174 Cleartext Transmission of Sensitive Information vulnerability in Netgear R6700 Firmware 1.0.4.120
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface.
network
low complexity
netgear CWE-319
7.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Netgear 502 8 474 462 149 1093