OSV 1.4.0 · unreviewed · 修改于 2022-02-01 08:00
发布时间
2022-01-26 08:01
GitHub 审查时间
—
NVD 发布时间
2022-01-26 00:15
源文件
advisories/unreviewed/2022/01/GHSA-h6cj-7c5m-52v5/GHSA-h6cj-7c5m-52v5.json
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of authentication required for a privileged request. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13325.
该公告没有提供结构化的受影响软件包信息。