← Vulnerability feed

Vulnerability record · CVE-2017-5521 · published 17 January 2017

CVE-2017-5521: NETGEAR router web management password disclosure via recovery token

Netgear · R6200 Firmware

Multiple NETGEAR router models expose the admin password through the web management server. When authentication is canceled and password recovery is disabled, the user is redirected to a page leaking a recovery token; supplying that token to /passwordrecovered.cgi?id=TOKEN returns the admin password. This gives full administrative control of the device.

8.1 CVSS 3.1 High CISA KEV since 8 Sep 2022 EPSS 89% · top 0.2%
8.1CVSS 3.1 base score, v2 4.3
89%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
13Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw yields unauthenticated admin password disclosure, is listed in CISA KEV, has a very high EPSS score, and public exploit code exists.

What it is

Multiple NETGEAR router models expose the admin password through the web management server. When authentication is canceled and password recovery is disabled, the user is redirected to a page leaking a recovery token; supplying that token to /passwordrecovered.cgi?id=TOKEN returns the admin password. This gives full administrative control of the device.

Impact

An attacker obtains the router's admin password, gaining full control of the device including its configuration and network traffic handling. This can enable further compromise of the connected network.

Attack surface

Reachable over the network against the router's web management server; exploitable remotely if remote management is enabled, and over LAN or WLAN otherwise. No authentication is required, and no user interaction is needed beyond the attacker's own requests.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2022-09-08, and EPSS shows a 30-day exploitation probability of 0.89353 (99.774th percentile). A public Exploit-DB entry (41205) exists, confirming public exploit code.

What to do

  • Apply the vendor firmware update referenced in NETGEAR advisory kb.netgear.com/30632 for all affected models.
  • If a device is end-of-life and cannot be patched, disconnect it from the network as CISA directs.
  • Disable remote management on the router's web interface unless strictly required.
  • Enable the password recovery feature with security questions, which causes the exploit to fail.
  • Restrict access to the router web management interface to trusted LAN segments only.

Detection

  • Monitor web server logs for requests to /passwordrecovered.cgi, especially with id parameters.
  • Alert on repeated or unusual access to the router's password recovery redirect page.
  • Watch for unexpected logins or configuration changes on the router following recovery page access.
  • Review router management access logs for connections from untrusted or external source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-5521 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability". Required action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use. Federal deadline 29 September 2022.

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-6277NETGEAR router cgi-bin command injection allows remote code executionMultiple NETGEAR router models fail to sanitize shell metacharacters in the path info passed to cgi-bin/, allowing remote command execution. The flaw…KEVEPSS 100%analysed9.8CVE-2021-45638Netgear d6220 firmware out-of-bounds write vulnerabilityCertain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.68, D6400 befor…EPSS 1.5%9.8CVE-2021-45610Netgear d6220 firmware classic buffer overflow vulnerabilityCertain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.66, D6400 before 1.0.0.100,…EPSS 1.4%9.8CVE-2021-45527Netgear rbk752 firmware classic buffer overflow vulnerabilityCertain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.68, D6400 before 1.0.0.102, D7000…EPSS 1.1%9.8CVE-2021-38516Netgear d6220 firmware vulnerabilityCertain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D700…EPSS 1.3%9.8CVE-2020-35796Netgear cbr40 firmware classic buffer overflow vulnerabilityCertain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D6220 before 1.0.0.60, …EPSS 1.3%9.8CVE-2018-21162Netgear d6400 firmware os command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86,…EPSS 3.4%9.8CVE-2018-21134Netgear r6700 firmware out-of-bounds write vulnerabilityCertain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6700 before 1.0.1.48, R7900 befor…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2017-5521), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.