CVE-2021-20168 describes a critical vulnerability in Netgear RAX43 firmware version 1.0.3.96, where insufficient protection of the UART interface allows for unauthorized access. An attacker with physical access can connect to the UART port, log in with default "admin:admin" credentials, and execute commands as the root user. This vulnerability carries a CVSS score of 6.8 (Medium) due to the high impact on confidentiality, integrity, and availability, though it requires physical proximity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.3.96CPE matchmatch criteria | cpe:2.3:o:netgear:rax43_firmware:1.0.3.96:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Netgear Nighthawk RAX43 Multiple Vulnerabilities
Dec 30, 2021Netgear Nighthawk RAX43 Multiple Vulnerabilities
Dec 30, 2021Netgear Nighthawk RAX43 Multiple Vulnerabilities
Dec 30, 2021