CVE-2021-35973

CRITICAL

NETGEAR WAC104 <1.0.4.15 - Auth Bypass

Title source: llm
STIX 2.1

Description

NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).

Scores

CVSS v3 9.8
EPSS 0.0193
EPSS Percentile 83.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-697
Status published
Products (1)
netgear/wac104_firmware < 1.0.4.15
Published Jun 30, 2021
Tracked Since Feb 18, 2026