CVE-2013-3072: NETGEAR WNDR4700 Firmware

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.

Affected products

  • NETGEAR WNDR4700 Firmware: version 1.0.0.34 only

Published 2019-11-14. Last modified 2026-06-16.