Security readout for executives and security teams
Plain-English summary
This CVE describes a symlink traversal issue in NETGEAR Centria WNDR4700 firmware 1.0.0.34. In business terms, a vulnerable router may mishandle file references and expose data outside an intended location. The bundle provides no CVSS score, affected CPEs, confirmed patch, or active exploitation evidence.
Executive priority
Treat this as an exposure-management issue unless WNDR4700 devices are found. If present, prioritize replacement or vendor-confirmed remediation because the device and firmware appear old and the provided evidence does not name a clear fix.
Technical view
The vulnerability is described only as symlink traversal in NETGEAR Centria WNDR4700 firmware 1.0.0.34. Symlink traversal generally means a component follows symbolic links across intended path boundaries. The provided sources do not define the vulnerable service, prerequisites, privileges, impact scope, or fixed version.
Likely exposure
Exposure is most likely limited to organizations or users still operating NETGEAR Centria WNDR4700 devices on firmware 1.0.0.34. The source bundle does not identify other affected products or versions.
Exploitation context
The CVE is not listed as KEV in the provided bundle. Public references exist from ISE, VulDB, SecurityFocus, and CVE records, but the bundle does not provide evidence of active exploitation or exploitation maturity.
Researcher notes
Evidence is sparse: no CVSS, CWE, CPE, exploit-status detail, vulnerable endpoint, or fixed WNDR4700 version is supplied. The NETGEAR reference in the bundle appears to discuss WNDR3700v4, so do not assume it fixes WNDR4700 without vendor confirmation.
Mitigation direction
- Inventory NETGEAR Centria WNDR4700 devices and record firmware versions.
- Check NETGEAR guidance for any applicable WNDR4700 firmware update or retirement recommendation.
- Restrict management and file-sharing interfaces to trusted networks only.
- Segment or replace affected routers if no supported fixed firmware exists.
- Avoid exposing router administration or storage services to the internet.
Validation and detection
- Confirm whether any WNDR4700 device runs firmware 1.0.0.34.
- Review router configuration for enabled storage, sharing, or management services.
- Check perimeter exposure for router administration and related services.
- Compare installed firmware against current NETGEAR support guidance.
- Document compensating controls where replacement or patching is not immediately possible.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2013-3073 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.ise.io/casestudies/exploiting-soho-routers/CVE reference · x_refsource_MISC
- https://www.ise.io/soho_service_hacks/CVE reference · x_refsource_MISC
- https://www.ise.io/wp-content/uploads/2017/07/soho_techreport.pdfCVE reference · x_refsource_MISC
- https://kb.netgear.com/24413/WNDR3700v4-Firmware-Version-1-0-1-52-Except-China-and-Russia-OnlyCVE reference · x_refsource_CONFIRM
- https://vuldb.com/?id.8471CVE reference · x_refsource_MISC
- https://www.securityfocus.com/bid/59307CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
