CVE-2024-28340: NETGEAR CBK40 Firmware

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

Affected products

  • NETGEAR CBK40 Firmware: version 2.5.0.28 only
  • NETGEAR CBK43 Firmware: version 2.5.0.28 only
  • NETGEAR CBR40 Firmware: version 2.5.0.28 only

Published 2024-03-12. Last modified 2026-06-17.