CVE-2025-4978
PoC moderateImproper Authentication in Netgear DGND3700 Router (/BRS_top.html)
CVE-2025-4978 is an improper authentication flaw (CWE-287) in the Basic Authentication component of the Netgear DGND3700 router firmware, triggered via the file /BRS_top.html. An unauthenticated remote attacker can manipulate requests to this endpoint to bypass authentication on the router's web management interface. Successful exploitation would give the attacker administrative access to the device's web UI, with high impact on confidentiality, integrity, and availability (CVSS 4.0: 9.3). Affected are Netgear DGND3700 units running firmware 1.1.00.15_1.00.15NA; the publicly available proof of concept references the DGND3700v2 variant as well, and other Netgear products may also be affected. The exploit is public and the vendor was notified in advance of disclosure; there is no confirmed in-the-wild exploitation yet, but EPSS assigns a 21% probability of exploitation within 30 days (97th percentile).
What to do: Check whether your DGND3700 runs firmware 1.1.00.15_1.00.15NA and upgrade to the latest firmware available on Netgear's support page if a fixed release is offered. Until then, disable or restrict remote (WAN) web management and limit access to the admin interface to the LAN. Because the public PoC also references the DGND3700v2, owners of that variant should verify their firmware and apply the same mitigations.
| Netgear DGND3700 firmware | 1.1.00.15_1.00.15NA (specifically named; other versions and the DGND3700v2 referenced in the public PoC are unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.
- Vendors
- netgear
- Products
- dgnd3700 firmware
- Weakness
- CWE-287
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.