{"id":"CVE-2021-41449","title":"A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web appli…","summary":"A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web appli…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-22"],"vendor":"netgear","product":"rax35_firmware","affected":["rax35_firmware < 1.0.4.102","rax38_firmware < 1.0.4.102","rax40_firmware < 1.0.4.102"],"patched":["rax35_firmware 1.0.4.102","rax38_firmware 1.0.4.102","rax40_firmware 1.0.4.102"],"published":"2021-12-09","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-41449","references":[{"url":"https://kb.netgear.com/000064405/Security-Advisory-for-Path-Traversal-on-Some-Routers-PSV-2021-0268","label":"cve@mitre.org"},{"url":"https://www.netgear.com/about/security/","label":"cve@mitre.org"},{"url":"http://netgear.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rax40.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kb.netgear.com/000064405/Security-Advisory-for-Path-Traversal-on-Some-Routers-PSV-2021-0268","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.netgear.com/about/security/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01558,"epssPercentile":0.73681,"ingestedAt":"2026-07-06T01:08:17.071Z","slug":"CVE-2021-41449","body":"## Overview\n\nA path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.\n\n## Affected\n\n- `rax35_firmware < 1.0.4.102`\n- `rax38_firmware < 1.0.4.102`\n- `rax40_firmware < 1.0.4.102`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `rax35_firmware 1.0.4.102`\n- `rax38_firmware 1.0.4.102`\n- `rax40_firmware 1.0.4.102`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}