Vulnerability threat dossier

CVE-2017-5521

netgearac1450

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

VTP deterministic threat61.4of 100 · CVSS excluded

VTP analyst assessment

NETGEAR router password disclosure

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence94%
Public exploitation · VTP factKEV

Assessment

Crafted requests to affected NETGEAR web-management services can disclose passwords; exploitation is remote when remote management is enabled and otherwise possible from LAN or WLAN access (CVSS 8.1). CISA KEV establishes global exploitation; EPSS 0.89353 is predictive only.

Why it matters

  • Credential disclosure can enable administrative access and subsequent router compromise.
  • Both remote-management exposure and local-network access provide viable paths.

Evidence

1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Affected device models, firmware, remote-management settings, and network access are unknown.

No exploit artifact, credential exposure evidence, or VTP telemetry is supplied.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Inventory listed NETGEAR devices and determine web-management exposure.

AI baseline history (1)
  1. BASELINE ASSESSED
    NETGEAR router password disclosuregpt-5.6-sol · high
Technical severityHIGHCVSS 8.1 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.89100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.89; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:5999664b9a4b3602d7ad4f674ca76f315d15fbd1ACTIVE
04

Event history

Threat timeline

  1. 02:3623 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 13:0824 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2017-5521.

  3. 00:0008 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 69 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 69 CVEs in this pinned revision. 69 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2016-0792CVE-2016-0870CVE-2016-10107CVE-2016-10108CVE-2016-10140CVE-2016-10401CVE-2016-2107CVE-2016-5649CVE-2016-8346CVE-2016-8722CVE-2016-8724CVE-2016-8725CVE-2016-9361CVE-2017-1000060CVE-2017-10931CVE-2017-14247CVE-2017-14252CVE-2017-14401CVE-2017-14402CVE-2017-14403CVE-2017-14404CVE-2017-14405CVE-2017-14942CVE-2017-17562CVE-2017-18365CVE-2017-20212CVE-2017-20213CVE-2017-20214CVE-2017-20215CVE-2017-20216CVE-2017-20221CVE-2017-20222CVE-2017-20223CVE-2017-20224CVE-2017-3143CVE-2017-3549CVE-2017-3599CVE-2017-5135CVE-2017-5367CVE-2017-5368CVE-2017-5521CVE-2017-5595CVE-2017-5689CVE-2017-5879CVE-2017-5982CVE-2017-6099CVE-2017-7315CVE-2017-7316CVE-2017-7317CVE-2017-7615CVE-2017-8221CVE-2017-8222CVE-2017-8223CVE-2017-8224CVE-2017-8225CVE-2017-8835CVE-2017-8836CVE-2017-8837CVE-2017-8838CVE-2017-8839CVE-2017-8840CVE-2017-8841CVE-2017-8917CVE-2017-9964CVE-2017-9965CVE-2017-9966CVE-2018-17153CVE-2025-34043CVE-2025-34099
Separate evidence group

Nuclei Templates v10.4.8 - Release Notes

New Templates Added: 112 | CVEs Added: 101 | First-time contributions: 22 🔥 Release Highlights 🔥 [CVE-2026-72898] Metabase - Unauthenticated SQL Injection (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-71362 ] Adobe Commerce/Magento - Customer Session Identity Switch (@0x_Akoko, @dinosn ) [critical] 🔥 [ CVE-2026-64849 ] MLflow Webhook SSRF - Unauth Full-Read via Redirect Bypass ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-64638] WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell) ( @flx | Nick Vidovic (greenhats)) [high] 🔥 [ CVE-2026-63077 ] JetBrains TeamCity < 2026.1.3, 2025.11.7 - RCE (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-59774] Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read ( @ashish-cybersec ) [critical] 🔥 [ CVE-2026-58644 ] Microsoft SharePoint Server - WS-Federation Deserialization RCE ( @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-57219] RabbitMQ Management - OAuth 2 Client Secret Disclosure ( @Aryu-RU ) [high] 🔥 [ CVE-2026-56270 ] Flowise <= 3.0.13 - Unauth OAuth Configuration Disclosure (@0x_Akoko, @pdteam ) [high] (vKEV) 🔥 [CVE-2026-53576] Kestra <= 1.3.20 - Remote Code Execution (@0x_Akoko, @pdteam , @Aryu-RU ) [critical] (vKEV) 🔥 [ CVE-2026-52806 ] Gogs <= 0.14.2 - Auth RCE via git rebase Argument Injection ( @dhiyaneshdk , @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-49049 ] JoomShaper Helix3 <=3.1.0 - Unauth Arbitrary JSON File Write ( @dhiyaneshdk , @pdteam ) [high] (vKEV) 🔥 [ CVE-2026-48939 ] Joomla iCagenda < 3.9.10 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-40217 ] LiteLLM < 1.25.0 - Remote Code Execution ( @ritikchaddha ) [high] (vKEV) 🔥 [ CVE-2026-34908 ] UniFi OS - Authentication Bypass via Path Traversal (..%2f) ( @Boreas37 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-20896 ] Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Auth Bypass ( @prithvee07 ) [critical] (vKEV) 🔥 [ CVE-2026-19478 ] GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method Invocation (@0x_Akoko, @dhiyaneshdk ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Corrected an unclosed string literal in the CVE-2026-0558 dsl matcher (PR #16950 ). Fixed a broken matcher in the newly added CVE-2026-3395 template (PR #16886 ). Fixed the username key structure in mysql-empty-password.yaml (PR #16939 ). Fixed indentation in kubernetes-metrics.yaml (PR #16934 ). Added the missing capture group to regex extractors in oracle-containers-panel, smtp-credentials-exposure and springboot-x-application-context (PR #16663 ). Corrected the max-request counter for CVE-2021-40822 (PR #16875 ). Corrected email and password variable names in CVE-2025-68613 (PR #16918 ). Renamed Wix-detect.yaml, cve-2026-44338 .yaml and CVE-2026-44381.yaml to match the naming convention (PRs #16731 , #16729 , #16730 ). Moved 22 invalid or rejected CVE templates to vulnerabilities (PR #16889 , Issue #16115 ). Removed CVE-2024-28752 .yaml (PR #16745 ). False Negatives CVE-2017-5521 , CVE-2017-7615 and CVE-2020-23575 — regexes were placed in word matchers, so these templates could never fire (PR #16666 ). nh-c2 — corrected a dsl matcher that could never match (PR #16739 ). CVE-2026-21858 — added a /rest/sentry.js fallback to detect n8n 1.65.0 through 1.111.x (PR #16888 ). CVE-2025-14847 — now detects vulnerable MongoDB 8.0.x via buildinfo read-size truncation (PR #16741 ). CVE-2025-32969 — removed an incorrect content_type matcher that suppressed matches (PR #16704 ). CVE-2023-37629 — closed the filename quote before the .php extension so the payload is well formed (PR #16709 ). False Positives CVE-2025-29927 — added negative matchers so WAF block pages returning HTTP 200 no longer match (PR #16870 , Issue #16782 ). wp-vr-view-xss and vrview-xss — no longer fire on hosts that escape the payload (PR #16912 ). wordpress-eol — tightened an over-broad version regex (PR #16752 ). CVE-2021-24139 — both conditions must now match rather than either (PR #16748 ). Marked prec

CVE-2015-7501CVE-2017-5521CVE-2017-7615CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-24139CVE-2021-40822CVE-2022-1281CVE-2022-29013CVE-2023-25826CVE-2023-37629CVE-2024-0200CVE-2024-13985CVE-2024-28752CVE-2024-37014CVE-2024-55890CVE-2024-56064CVE-2024-57726CVE-2025-0520CVE-2025-11953CVE-2025-13342CVE-2025-13528CVE-2025-14847CVE-2025-20282CVE-2025-26399CVE-2025-29927CVE-2025-32969CVE-2025-68613CVE-2025-71324CVE-2026-0558CVE-2026-0717CVE-2026-10768CVE-2026-1115CVE-2026-11387CVE-2026-12394CVE-2026-13001CVE-2026-13147CVE-2026-14483CVE-2026-14894CVE-2026-15733CVE-2026-15826CVE-2026-16268CVE-2026-17505CVE-2026-17532CVE-2026-17594CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25231CVE-2026-25895CVE-2026-2614CVE-2026-26217CVE-2026-27542CVE-2026-27796CVE-2026-3001CVE-2026-30965CVE-2026-32255CVE-2026-3395CVE-2026-34908CVE-2026-34976CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-40280CVE-2026-4060CVE-2026-41042CVE-2026-41432CVE-2026-42461CVE-2026-44338CVE-2026-44381CVE-2026-45332CVE-2026-45695CVE-2026-48030CVE-2026-48939CVE-2026-49049CVE-2026-49069CVE-2026-50160CVE-2026-5032CVE-2026-52806CVE-2026-53519CVE-2026-53576CVE-2026-53629CVE-2026-53753CVE-2026-53755CVE-2026-53976CVE-2026-54917CVE-2026-55087CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-58138CVE-2026-58644CVE-2026-59774CVE-2026-61511CVE-2026-61808CVE-2026-63030CVE-2026-63077CVE-2026-64638CVE-2026-64849CVE-2026-65442CVE-2026-65919CVE-2026-67208CVE-2026-6826CVE-2026-6854CVE-2026-69084CVE-2026-69251CVE-2026-71209CVE-2026-71362CVE-2026-72898CVE-2026-8236CVE-2026-8237CVE-2026-8857CVE-2026-9506
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.4vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction17.85 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Unknown
CPE records
26
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.