CVE-2022-41545

MEDIUM

Netgear C7800 Router <6.01.07 - Info Disclosure

Title source: llm
STIX 2.1

Description

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.

References (4)

Core 4

Scores

CVSS v3 6.4
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-319
Status published
Products (1)
netgear/c7800_firmware 6.01.07
Published Feb 18, 2025
Tracked Since Feb 18, 2026