Vulnerability record · CVE-2017-5521 · published 17 January 2017
CVE-2017-5521: NETGEAR router web management password disclosure via recovery token
Netgear · R6200 Firmware
Multiple NETGEAR router models expose the admin password through the web management server. When authentication is canceled and password recovery is disabled, the user is redirected to a page leaking a recovery token; supplying that token to /passwordrecovered.cgi?id=TOKEN returns the admin password. This gives full administrative control of the device.
Description
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw yields unauthenticated admin password disclosure, is listed in CISA KEV, has a very high EPSS score, and public exploit code exists.
What it is
Multiple NETGEAR router models expose the admin password through the web management server. When authentication is canceled and password recovery is disabled, the user is redirected to a page leaking a recovery token; supplying that token to /passwordrecovered.cgi?id=TOKEN returns the admin password. This gives full administrative control of the device.
Impact
An attacker obtains the router's admin password, gaining full control of the device including its configuration and network traffic handling. This can enable further compromise of the connected network.
Attack surface
Reachable over the network against the router's web management server; exploitable remotely if remote management is enabled, and over LAN or WLAN otherwise. No authentication is required, and no user interaction is needed beyond the attacker's own requests.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-09-08, and EPSS shows a 30-day exploitation probability of 0.89353 (99.774th percentile). A public Exploit-DB entry (41205) exists, confirming public exploit code.
What to do
- Apply the vendor firmware update referenced in NETGEAR advisory kb.netgear.com/30632 for all affected models.
- If a device is end-of-life and cannot be patched, disconnect it from the network as CISA directs.
- Disable remote management on the router's web interface unless strictly required.
- Enable the password recovery feature with security questions, which causes the exploit to fail.
- Restrict access to the router web management interface to trusted LAN segments only.
Detection
- Monitor web server logs for requests to /passwordrecovered.cgi, especially with id parameters.
- Alert on repeated or unusual access to the router's password recovery redirect page.
- Watch for unexpected logins or configuration changes on the router following recovery page access.
- Review router management access logs for connections from untrusted or external source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-5521 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability". Required action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use. Federal deadline 29 September 2022.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability | Vendor Advisory |
| http://www.securityfocus.com/bid/95457 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41205/ | ExploitThird Party AdvisoryVDB Entry |
| http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability | Vendor Advisory |
| http://www.securityfocus.com/bid/95457 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41205/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5521 | US Government Resource |
Track CVE-2017-5521 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5521), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.