CVE-2015-8288 describes a critical vulnerability in NETGEAR D3600 and D6000 devices running firmware version 1.0.0.49 and earlier. The flaw stems from the use of a hardcoded private key across all installations, allowing remote attackers to bypass cryptographic protections if they obtain the key from any device. This vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high complexity but potentially high impact on confidentiality. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.49CPE matchmatch criteria | cpe:2.3:o:netgear:d3600_firmware:1.0.0.49:*:*:*:*:*:*:* | ||
<= 1.0.0.49CPE matchmatch criteria | cpe:2.3:o:netgear:d6000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.