ID
VAR-E-201502-0069
TITLE
Multiple NetGear Routers SOAP Service Authentication Bypass Vulnerability
Trust: 0.3
DESCRIPTION
Multiple NetGear Routers are prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain potentially sensitive information.
NetGear WNDR3700v4 V1.0.0.4SH, WNDR3700v4 V1.0.1.52, WNR2200 V1.0.1.88, WNR2500 V1.0.0.24 are vulnerable.
Trust: 0.3
AFFECTED PRODUCTS
vendor: | netgear | model: | wnr2500 | scope: | eq | version: | 1.0.0.24 | Trust: 0.3 |
vendor: | netgear | model: | wnr2200 | scope: | eq | version: | 1.0.1.88 | Trust: 0.3 |
vendor: | netgear | model: | wndr3700v4 | scope: | eq | version: | 1.0.1.52 | Trust: 0.3 |
vendor: | netgear | model: | wndr3700v4 1.0.0.4sh | scope: | - | version: | - | Trust: 0.3 |
EXPLOIT
The following proof-of-concept code is available:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/72640.rb">/data/vulnerabilities/exploits/72640.rb</a></li>
Trust: 0.3
PRICE
Free
Trust: 0.3
TYPE
Access Validation Error
Trust: 0.3
CREDITS
Peter Adkins
Trust: 0.3
EXTERNAL IDS
db: | BID | id: | 72640 | Trust: 0.3 |
REFERENCES
url: | https://github.com/darkarnium/secpub/tree/master/netgear/soapwndr | Trust: 0.3 |
url: | http://www.netgear.com | Trust: 0.3 |
SOURCES
db: | BID | id: | 72640 |
LAST UPDATE DATE
2022-07-27T09:21:48.098000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 72640 | date: | 2015-02-17T00:00:00 |
SOURCES RELEASE DATE
db: | BID | id: | 72640 | date: | 2015-02-17T00:00:00 |