ID

VAR-201302-0535


TITLE

NetGear DGN1000B Wireless Router Multiple Security Vulnerabilities

Trust: 0.9

sources: BID: 57836 // CNNVD: CNNVD-201302-281

DESCRIPTION

The NetGear DGN1000B is a wireless router device. The NetGear DGN1000B has multiple security vulnerabilities, including OS command injection in the UPNP configuration, insecure encrypted storage, and cross-site scripting vulnerabilities, allowing attackers to exploit vulnerabilities to obtain sensitive information and control application devices. A command-injection vulnerability 2. An information-disclosure vulnerability 3. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks

Trust: 0.81

sources: CNVD: CNVD-2013-01020 // BID: 57836

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-01020

AFFECTED PRODUCTS

vendor:netgearmodel:dgn1000bscope:eqversion:1.1.00.45

Trust: 0.6

vendor:netgearmodel:dgn1000bscope:eqversion:1.1.00.24

Trust: 0.6

sources: CNVD: CNVD-2013-01020

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201302-281

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 57836

EXTERNAL IDS

db:BIDid:57836

Trust: 1.5

db:CNVDid:CNVD-2013-01020

Trust: 0.6

db:CNNVDid:CNNVD-201302-281

Trust: 0.6

sources: CNVD: CNVD-2013-01020 // BID: 57836 // CNNVD: CNNVD-201302-281

REFERENCES

url:http://www.s3cur1ty.de/node/660

Trust: 0.6

url:http://www.securityfocus.com/bid/57836

Trust: 0.6

sources: CNVD: CNVD-2013-01020 // CNNVD: CNNVD-201302-281

CREDITS

Michael Messner

Trust: 0.9

sources: BID: 57836 // CNNVD: CNNVD-201302-281

SOURCES

db:CNVDid:CNVD-2013-01020
db:BIDid:57836
db:CNNVDid:CNNVD-201302-281

LAST UPDATE DATE

2022-05-17T02:07:15.539000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-01020date:2013-02-19T00:00:00
db:BIDid:57836date:2013-04-04T08:17:00
db:CNNVDid:CNNVD-201302-281date:2013-02-21T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-01020date:2013-02-19T00:00:00
db:BIDid:57836date:2013-02-06T00:00:00
db:CNNVDid:CNNVD-201302-281date:2013-02-21T00:00:00