Wac104 Firmware
by Netgear
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35973 | Cri | 0.64 | 9.8 | 0.03 | Jun 30, 2021 | NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the ¤tsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This… | ||
| CVE-2021-44262 | Hig | 0.49 | 7.5 | 0.02 | Mar 17, 2022 | A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device. | ||
| CVE-2020-35788 | Hig | 0.49 | 7.6 | 0.00 | Dec 30, 2020 | NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user. | ||
| CVE-2021-38532 | Med | 0.44 | 6.8 | 0.01 | Aug 11, 2021 | NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings. | ||
| CVE-2021-44261 | Med | 0.36 | 5.3 | 0.20 | Mar 17, 2022 | A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device. |
- risk 0.64cvss 9.8epss 0.03
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the ¤tsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This…
- risk 0.49cvss 7.5epss 0.02
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.
- risk 0.49cvss 7.6epss 0.00
NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.
- risk 0.44cvss 6.8epss 0.01
NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.
- risk 0.36cvss 5.3epss 0.20
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.