VYPR
Unrated severityNVD Advisory· Published Jun 18, 2020· Updated Aug 4, 2024

CVE-2020-14428

CVE-2020-14428

Description

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR Orbi WiFi systems before firmware 3.2.15.25 expose admin credentials, enabling local network attackers to gain full administrative control.

Vulnerability

An administrative credential disclosure vulnerability exists in certain NETGEAR Orbi WiFi system models. Affected devices include RBK752, RBK753, RBK753S, RBR750, RBS750, RBK842, RBR840, RBS840, RBK852, RBK853, RBR850, and RBS850 running firmware versions prior to 3.2.15.25 [1]. The vulnerability allows an attacker to obtain the administrative credentials of the device, potentially without any prior authentication or user interaction.

Exploitation

An attacker with access to the local network can exploit this vulnerability to retrieve the administrative credentials. The exact attack vector is not detailed in the advisory, but it likely involves a network service or API that improperly exposes sensitive information. No user interaction is required, and the attacker does not need to be authenticated to the device [1].

Impact

Successful exploitation grants the attacker administrative access to the affected WiFi system. This enables full control over the device, including the ability to change configuration settings, monitor network traffic, modify security policies, and potentially pivot to other devices on the network. The disclosure of admin credentials compromises the confidentiality and integrity of the entire network [1].

Mitigation

NETGEAR has released firmware version 3.2.15.25 to address this vulnerability. Users are strongly advised to download and install the latest firmware for their specific model from the NETGEAR Support website. No workarounds are provided, and the vulnerability remains if the device is not updated [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.