CVE-2017-5521
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN.
Leer descripción completaMostrar menos
When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 89%
- Percentil entre todas las CVEs puntuadas: 100
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CISA KEV — explotada activamente
- Añadida al catálogo: 8/9/2022
- Plazo de remediación: 29/9/2022
- Uso conocido en ransomware: Unknown
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access90 % - Impacto secundario
T1552.001Credentials In Filescredential access85 %
Acceso no autenticado al servidor web del router mediante solicitudes artesanales; exposición de credenciales administrativas via token de recuperación en /passwordrecovered.cgi sin validación adecuada.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (13)
CWE
- NVD-CWE-noinfo
Referencias
- http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability
- http://www.securityfocus.com/bid/95457
- https://www.exploit-db.com/exploits/41205/
- http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability
- http://www.securityfocus.com/bid/95457
- https://www.exploit-db.com/exploits/41205/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5521
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-5521",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2017-5521",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-04T20:47:45.282013Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-01-17T09:59:00.333",
"references": [
{
"url": "http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/95457",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/41205/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/95457",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/41205/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5521",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en dispositivos NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900 y R8000. Son propensos a revelar la contraseña a través de peticiones simples manipuladas al servidor de gestión de la web. El error es explotable remotamente si la opción de gestión remota está activada, y también puede ser explotado dado el acceso al router a través de LAN o WLAN. Cuando se trata de acceder al panel web, se pide al usuario que se autentique; si la autenticación se cancela y la recuperación de contraseña no está habilitada, el usuario es redirigido a una página que revela un token de recuperación de contraseña. Si un usuario proporciona el token correcto a la página /passwordrecovered.cgi?id=TOKEN (y la recuperación de contraseña no está habilitada), recibirán la contraseña de administrador para el router. Si la recuperación de contraseña está habilitada, la explotación fallará, ya que pedirá al usuario preguntas para la recuperación que fueron previamente establecidas cuando se habilitó esa característica. Esto es persistente (incluso tras la inhabilitación de la opción de recuperación, la explotación fallará) porque el router preguntará por las preguntas de seguridad."
}
],
"lastModified": "2026-06-17T01:20:39.923",
"cisaActionDue": "2022-09-29",
"cisaExploitAdd": "2022-09-08",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:r6200_firmware:1.0.1.56_1.0.43:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C1769F8-B2CB-465B-85B8-9D7AC25C63CB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:r6200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8A466B29-3ADA-46D9-824C-8DF9160B7DD7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:r6300_firmware:1.0.2.78_1.0.58:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A99D1C-CABE-4526-B3B7-3708C0E18AC4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:r6300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9597966A-B13C-4098-838B-EC9AA8DE443D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:vegn2610_firmware:1.0.0.36:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D329D85-C180-426E-B430-9FEDE5C77F25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:vegn2610:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0967FC76-F977-4D18-B570-9444459A19FE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:ac1450_firmware:1.0.0.34_10.0.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91292776-92F7-4089-86FC-7569C8F940DE"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:ac1450:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E4BA18B2-8234-4C26-B865-741D467C5EBE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:wnr1000v3_firmware:1.0.2.68_60.0.93:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E35A89F-44C7-496C-B61B-652989EDE438"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:wnr1000v3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "252E5C7B-EF02-4374-A43E-02FAA9E697D0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:wndr3700v3_firmware:1.0.0.40_1.0.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D59A6F9-0359-4AB4-AD0F-1D6044D59409"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:wndr3700v3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "603836E6-E7FF-43C7-A410-8BD9D0950F7C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:wndr4000_firmware:1.0.2.4_9.1.86:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91561A20-30F5-4163-9178-5FC32897F827"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:wndr4000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1C34EC74-D6F1-46F1-B47E-E62793171427"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:wndr4500_firmware:1.0.1.44_1.0.73:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9874914-4D90-493F-BD2B-40FFF1737F58"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:wndr4500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7E9F459C-B628-402A-AF4A-72E08FE41837"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:d6400_firmware:1.0.0.44:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3EB5F49-3628-4418-AF36-AF8FD6F5BA25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:d6400:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7D30939B-86E3-4C78-9B05-686B4994C8B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:d6220_firmware:1.0.0.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECD46588-5866-4159-85E1-58B0D1F98406"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:d6220:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F3EEA190-2E9C-4586-BF81-B115532FBA23"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:d6300_firmware:1.0.0.96:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B15B85C-F099-4584-9F59-1CFC3275D625"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:d6300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "78542C95-85CC-43E5-9F0E-B12DDD5B79C4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:d6300b_firmware:1.0.0.40:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0CE8A8F-7894-4140-8E4B-84153C5A6B13"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:d6300b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "37B89703-CAFB-43F6-8880-90349F8ED856"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:dgn2200bv4_firmware:1.0.0.68:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1CDFE4F-6C5C-4B10-926E-92C7759D60EF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:dgn2200bv4:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9C78A475-9DDF-432B-A94A-01EFAC7DC70D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org",
"cisaRequiredAction": "Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.",
"cisaVulnerabilityName": "NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability"
}