ID

VAR-E-201306-0696


TITLE

Netgear WPN824v3 Unauthorized Config Download

Trust: 0.5

sources: PACKETSTORM: 121865

DESCRIPTION

Netgear WPN824v3 allows for a remote party to download the configuration file unauthenticated.

Trust: 0.5

sources: PACKETSTORM: 121865

AFFECTED PRODUCTS

vendor:netgearmodel:wpn824v3scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 121865

EXPLOIT

Title:
======
Netgear WPN824v3 Unauthorized Config Download

Date:
=====
2013-06-03

Introduction:
=============
The Netgear RangeMax Wireless Router (model WPN824v3) allows to download
the config file without authorization.

Status:
========
Published

Affected Products:
==================
Netgear WPN824v3

Vendor Homepage:
================
http://support.netgear.com/product/WPN824v3

Exploitation-Technique:
=======================
Local and Remote

Details:
========
I found a bug in the Netgear WPN824v3 wireless router, everyone is able
to download the full config file without authorization.
Unfortunately the config file is not htaccess protected.
Tested with latest firmware V1.0.8_1.0.6.

Proof of Concept:
=================
The vulnerability can be exploited with your browser:

http://[local-ip]/cgi-bin/NETGEAR_wpn824v3.cfg

If remote management is enabled:

http://[remote-ip]:8080/cgi-bin/NETGEAR_wpn824v3.cfg

Workaround:
=========
Disable the remote management feature!

Author:
========
Jens Regel <jens@loxiran.de>

Trust: 0.5

sources: PACKETSTORM: 121865

EXPLOIT HASH

LOCAL

SOURCE

md5: d55c0037ea595e02934c4ec94a8c58be
sha-1: 8d07f1581a471363cb2faab59503b277e6db7556
sha-256: 06e9758cc624e50c9ef6019e428d78a591a6733fb0bb99f6c0f03c6e3a08dc24
md5: d55c0037ea595e02934c4ec94a8c58be

Trust: 0.5

sources: PACKETSTORM: 121865

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 121865

TAGS

tag:exploit

Trust: 0.5

tag:remote

Trust: 0.5

sources: PACKETSTORM: 121865

CREDITS

Jens Regel

Trust: 0.5

sources: PACKETSTORM: 121865

EXTERNAL IDS

db:PACKETSTORMid:121865

Trust: 0.5

sources: PACKETSTORM: 121865

SOURCES

db:PACKETSTORMid:121865

LAST UPDATE DATE

2022-07-27T09:12:05.828000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:121865date:2013-06-03T23:36:05