Netgear WG602 Wireless Access Point Default Backdoor Account Vulnerability
BID:10459
Info
Netgear WG602 Wireless Access Point Default Backdoor Account Vulnerability
| Bugtraq ID: | 10459 |
| Class: | Design Error |
| CVE: |
CVE-2004-2556 CVE-2004-2557 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2004 12:00AM |
| Updated: | Jun 03 2004 12:00AM |
| Credit: | Discovery is credited to Tom Knienieder <[email protected]>. |
| Vulnerable: |
NetGear WG602 Access Point Firmware 1.7.14 NetGear WG602 Access Point Firmware 1.04.0 |
| Not Vulnerable: |
NetGear WG602v2 Access Point Firmware 3.2 RC6 NetGear WG602v2 Access Point Firmware 3.1 RC5 NetGear WG602v2 Access Point Firmware 3.1 RC2 NetGear WG602v2 Access Point Firmware 2.0 RC5 NetGear WG602v2 Access Point NetGear WG602 Access Point Firmware 1.7.15 |
Discussion
Netgear WG602 Wireless Access Point Default Backdoor Account Vulnerability
Netgear WG602 reportedly contains a default administrative account. This issue can allow a remote attacker to gain administrative access to the device.
Netgear WG602 access point with firmware version 1.04.0 is reportedly affected by this issue. It is likely that other versions of the firmware are also vulnerable. It is reported that the new version (1.7.14) of the Firmware for WG602 is vulnerable to this issue as well, however, the username and password for the backdoor account has been changed.
Netgear WG602 reportedly contains a default administrative account. This issue can allow a remote attacker to gain administrative access to the device.
Netgear WG602 access point with firmware version 1.04.0 is reportedly affected by this issue. It is likely that other versions of the firmware are also vulnerable. It is reported that the new version (1.7.14) of the Firmware for WG602 is vulnerable to this issue as well, however, the username and password for the backdoor account has been changed.
Exploit / POC
Netgear WG602 Wireless Access Point Default Backdoor Account Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Netgear WG602 Wireless Access Point Default Backdoor Account Vulnerability
Solution:
It is alleged that the vendor has released NetGear WG602 Access Point Firmware 1.7.15 to address this issue. This information is not confirmed at the moment. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is alleged that the vendor has released NetGear WG602 Access Point Firmware 1.7.15 to address this issue. This information is not confirmed at the moment. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Netgear WG602 Wireless Access Point Default Backdoor Account Vulnerability
References:
References:
- Netgear Support Page (Netgear)
- Netgear WG602 Access Point (Netgear)
- RE: [Full-Disclosure] Re: Netgear WG602 Accesspoint vulnerability ("Jan-Peter Koopmann"
) - Re: Netgear WG602 Accesspoint vulnerability (RISKO Gergely
) - Re: Netgear WG602 Accesspoint vulnerability (Mathias Kuester
) - Re: Netgear WG602 Accesspoint vulnerability ([email protected])
- Re: Netgear WG602 Accesspoint vulnerability (Jaco Swart
) - Re: Netgear WG602 Accesspoint vulnerability (
) - Re: Netgear WG602 Accesspoint vulnerability (James Garrison
)