CVE-2012-6341
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext.
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than CVE-2012-6340.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- netgear/wgr614v9 firmware · netgear/wgr614v7 firmware
- Source
- cve@mitre.org
References
- https://packetstormsecurity.com/files/date/2012-12-14/Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/525042Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/date/2012-12-14/Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/525042Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.