U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-41545

Change History

CVE Modified by CVE 2/18/2025 1:15:13 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://seclists.org/fulldisclosure/2025/Feb/12

New CVE Received from MITRE 2/18/2025 1:15:13 PM

Action Type Old Value New Value
Added Description

								
							
							
						
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.
Added Reference

								
							
							
						
https://seclists.org/fulldisclosure/2025/Feb/12
Added Reference

								
							
							
						
https://www.netgear.com/about/security/
Added Reference

								
							
							
						
https://www.netgear.com/images/datasheet/networking/cablemodems/C7800.pdf