CVE-2021-45493

HIGH

NETGEAR RAX35 RAX38 RAX40 < 1.0.4.102 - Unauthenticated Admin Credential Exposure

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

Scores

CVSS v3 7.6
EPSS 0.0032
EPSS Percentile 55.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Details

CWE
CWE-200
Status published
Products (3)
netgear/rax35_firmware < 1.0.4.102
netgear/rax38_firmware < 1.0.4.102
netgear/rax40_firmware < 1.0.4.102
Published Dec 26, 2021
Tracked Since Feb 18, 2026