| [Japanese] | |
JVNDB-2026-000018 | |
Undocumented "TelnetEnable" functionality of End of Service NETGEAR products | |
| Overview | |
Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box. | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V3 Severity:
Base Metrics 7.5 (High) [IPA Score]
| |
| Affected Products | |
|
| |
NETGEAR | |
According to the developer, (1) PR2000 was not sold in Japan, (2) all NETGEAR products currently supported (at the time of this writing) don't have "TelnetEnable" functionality, (3) NETGEAR will not verify issues on obsolete (non-supported) products. | |
| Impact | |
Telnet service may be activated by a magic packet sent to the LAN interface of the affected product. | |
| Solution | |
[Stop using the products] | |
| Vendor Information | |
NETGEAR | |
| CWE (What is CWE?) | |
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2026/01/30 |
| Date First Published | 2026/01/30 |
| Date Last Updated | 2026/01/30 |


