CVE-2025-4980

A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vulnerability affects unknown code of the file /currentsetting.htm of the component mini_http. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:dgnd3700_firmware:1.1.00.15_1.00.15na:*:*:*:*:*:*:*
cpe:2.3:h:netgear:dgnd3700:v2:*:*:*:*:*:*:*

History

12 Jun 2025, 16:21

Type Values Removed Values Added
CPE cpe:2.3:h:netgear:dgnd3700:v2:*:*:*:*:*:*:*
cpe:2.3:o:netgear:dgnd3700_firmware:1.1.00.15_1.00.15na:*:*:*:*:*:*:*
Summary
  • (es) Se ha detectado una vulnerabilidad en Netgear DGND3700 1.1.00.15_1.00.15NA, clasificada como problemática. Esta vulnerabilidad afecta al código desconocido del archivo /currentsetting.htm del componente mini_http. La manipulación provoca la divulgación de información. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. Otros productos también podrían verse afectados. Se contactó al proveedor con antelación para informarle sobre esta divulgación.
First Time Netgear dgnd3700
Netgear
Netgear dgnd3700 Firmware
References () https://github.com/at0de/my_vulns/blob/main/Netgear/DGND3700v2/currentsetting.md - () https://github.com/at0de/my_vulns/blob/main/Netgear/DGND3700v2/currentsetting.md - Exploit
References () https://vuldb.com/?ctiid.309640 - () https://vuldb.com/?ctiid.309640 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.309640 - () https://vuldb.com/?id.309640 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.564714 - () https://vuldb.com/?submit.564714 - Third Party Advisory, VDB Entry
References () https://www.netgear.com/ - () https://www.netgear.com/ - Product

20 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-20 14:15

Updated : 2025-06-12 16:21


NVD link : CVE-2025-4980

Mitre link : CVE-2025-4980

CVE.ORG link : CVE-2025-4980


JSON object : View

Products Affected

netgear

  • dgnd3700
  • dgnd3700_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control