CVE-2020-14429
Certain NETGEAR devices are affected by disclosure of administrative credentials.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects MK62 before 1.0.4.92, MK63 before 1.0.4.92, MR60 before 1.0.4.92, MS60 before 1.0.4.92, RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBS750 before 3.2.15.25, RBR750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- netgear/mk62 firmware · netgear/mk63 firmware · netgear/mr60 firmware · netgear/ms60 firmware · netgear/rbk752 firmware · netgear/rbk753 firmware · netgear/rbk753s firmware · netgear/rbs750 firmware · netgear/rbr750 firmware · netgear/rbk842 firmware · netgear/rbr840 firmware · netgear/rbs840 firmware · netgear/rbk852 firmware · netgear/rbk853 firmware · netgear/rbr850 firmware · netgear/rbs850 firmware
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.