CVE-2024-4235 is a medium-severity vulnerability affecting the Netgear DG834Gv5 router (firmware version 1.6.01.34) within its web management interface. This flaw, categorized as cleartext storage of sensitive information (CWE-312), allows an attacker to remotely access sensitive data due to inadequate protection. While the CVSS score is 4.9, indicating a medium severity, the attack requires high privileges (PR:H) but is low complexity (AC:L) and can lead to high confidentiality impact (C:H). There is no evidence of active exploitation, and despite public disclosure of the exploit, there are no known Metasploit modules, Nuclei templates, or ExploitDB entries, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.01.34CPE matchmatch criteria | cpe:2.3:o:netgear:dg834gv5_firmware:1.6.01.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.