ID

VAR-E-201502-0069


TITLE

Multiple NetGear Routers SOAP Service Authentication Bypass Vulnerability

Trust: 0.3

sources: BID: 72640

DESCRIPTION

Multiple NetGear Routers are prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain potentially sensitive information.
NetGear WNDR3700v4 V1.0.0.4SH, WNDR3700v4 V1.0.1.52, WNR2200 V1.0.1.88, WNR2500 V1.0.0.24 are vulnerable.

Trust: 0.3

sources: BID: 72640

AFFECTED PRODUCTS

vendor:netgearmodel:wnr2500scope:eqversion:1.0.0.24

Trust: 0.3

vendor:netgearmodel:wnr2200scope:eqversion:1.0.1.88

Trust: 0.3

vendor:netgearmodel:wndr3700v4scope:eqversion:1.0.1.52

Trust: 0.3

vendor:netgearmodel:wndr3700v4 1.0.0.4shscope: - version: -

Trust: 0.3

sources: BID: 72640

EXPLOIT

The following proof-of-concept code is available:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/72640.rb">/data/vulnerabilities/exploits/72640.rb</a></li>

Trust: 0.3

sources: BID: 72640

PRICE

Free

Trust: 0.3

sources: BID: 72640

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 72640

CREDITS

Peter Adkins

Trust: 0.3

sources: BID: 72640

EXTERNAL IDS

db:BIDid:72640

Trust: 0.3

sources: BID: 72640

REFERENCES

url:https://github.com/darkarnium/secpub/tree/master/netgear/soapwndr

Trust: 0.3

url:http://www.netgear.com

Trust: 0.3

sources: BID: 72640

SOURCES

db:BIDid:72640

LAST UPDATE DATE

2022-07-27T09:21:48.098000+00:00


SOURCES UPDATE DATE

db:BIDid:72640date:2015-02-17T00:00:00

SOURCES RELEASE DATE

db:BIDid:72640date:2015-02-17T00:00:00