ID

VAR-E-201306-0087


EDB ID

25969


TITLE

Netgear WPN824v3 - Unauthorized Configuration Download - Hardware webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 25969

DESCRIPTION

Netgear WPN824v3 - Unauthorized Configuration Download. CVE-94102 . webapps exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 25969

AFFECTED PRODUCTS

vendor:netgearmodel:wpn824v3scope: - version: -

Trust: 1.6

sources: EXPLOIT-DB: 25969 // EDBNET: 47967

EXPLOIT

Title:
======
Netgear WPN824v3 Unauthorized Config Download

Date:
=====
2013-06-03

Introduction:
=============
The Netgear RangeMax Wireless Router (model WPN824v3) allows to download
the config file without authorization.

Status:
========
Published

Affected Products:
==================
Netgear WPN824v3

Vendor Homepage:
================
http://support.netgear.com/product/WPN824v3

Exploitation-Technique:
=======================
Local and Remote

Details:
========
I found a bug in the Netgear WPN824v3 wireless router, everyone is able
to download the full config file without authorization.
Unfortunately the config file is not htaccess protected.
Tested with latest firmware V1.0.8_1.0.6.

Proof of Concept:
=================
The vulnerability can be exploited with your browser:

http://[local-ip]/cgi-bin/NETGEAR_wpn824v3.cfg

If remote management is enabled:

http://[remote-ip]:8080/cgi-bin/NETGEAR_wpn824v3.cfg

Workaround:
=========
Disable the remote management feature!

Author:
========
Jens Regel <jens@loxiran.de>

Trust: 1.0

sources: EXPLOIT-DB: 25969

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 25969

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 25969

TYPE

Unauthorized Configuration Download

Trust: 1.0

sources: EXPLOIT-DB: 25969

CREDITS

Jens Regel

Trust: 0.6

sources: EXPLOIT-DB: 25969

EXTERNAL IDS

db:EXPLOIT-DBid:25969

Trust: 1.6

db:EDBNETid:47967

Trust: 0.6

sources: EXPLOIT-DB: 25969 // EDBNET: 47967

REFERENCES

url:https://www.exploit-db.com/exploits/25969/

Trust: 0.6

sources: EDBNET: 47967

SOURCES

db:EXPLOIT-DBid:25969
db:EDBNETid:47967

LAST UPDATE DATE

2022-07-27T09:12:06.209000+00:00


SOURCES RELEASE DATE

db:EXPLOIT-DBid:25969date:2013-06-05T00:00:00
db:EDBNETid:47967date:2013-06-05T00:00:00