CVE-2017-5521 is an authentication-related information disclosure vulnerability affecting multiple NETGEAR router models, including R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000. The web management interface exposes a password recovery token after an authentication attempt is canceled when password recovery is not enabled. An attacker who obtains this token can submit it to the password recovery endpoint and retrieve the router's administrator password in clear form. The issue is reachable over the local network via LAN or WLAN, and remotely when remote management is enabled. The vulnerability results from improper protection of sensitive credential recovery functionality and insufficient authorization checks around password recovery flows.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module: 'netgear_password_disclosure.rb'. The module targets NETGEAR routers vulnerable to CVE-2017-5521, which allows unauthenticated attackers to retrieve the administrator password. The exploit works by first checking if the target device is a NETGEAR router (by looking for a 'WWW-Authenticate' header), then requesting a token from '/unauth.cgi', and finally using that token to query '/passwordrecovered.cgi' to extract the admin credentials. The module is written in Ruby and leverages Metasploit's HTTP client mixin. No hardcoded payload is delivered; instead, the exploit automates the credential extraction process. The only file in the repository is the Metasploit module itself, and it is fully operational for credential disclosure on affected NETGEAR routers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.