← Zuruck zu CVEs
CVE-2022-41545
MEDIUM6.4
Beschreibung
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.
CVE Details
CVSS v3.1 Bewertung6.4
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorADJACENT_NETWORK
KomplexitatHIGH
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht2/18/2025
Zuletzt geandert6/6/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
netgear:c7800netgear:c7800_firmware
Schwachen (CWE)
CWE-319
Referenzen
https://seclists.org/fulldisclosure/2025/Feb/12(cve@mitre.org)
https://www.netgear.com/about/security/(cve@mitre.org)
http://seclists.org/fulldisclosure/2025/Feb/12(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.