Vulnerabilities > Netgear > Wac104 Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-35973 Incorrect Comparison vulnerability in Netgear Wac104 Firmware 1.0.4.13
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866.
network
low complexity
netgear CWE-697
critical
9.8