NETGEAR Wireless Cable Modem Gateway Cross Site Request Forgery and Security Bypass Vulnerabilities
BID:49692
Info
NETGEAR Wireless Cable Modem Gateway Cross Site Request Forgery and Security Bypass Vulnerabilities
| Bugtraq ID: | 49692 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2011 12:00AM |
| Updated: | Sep 20 2011 12:00AM |
| Credit: | Sense of Security Labs |
| Vulnerable: |
NetGear Wireless Cable Modem Gateway CG814WG 3.9.26 R14 |
| Not Vulnerable: |
NetGear Wireless Cable Modem Gateway CG814WG 3.9.26 R15 |
Discussion
NETGEAR Wireless Cable Modem Gateway Cross Site Request Forgery and Security Bypass Vulnerabilities
NETGEAR Wireless Cable Modem Gateway is prone to a cross-site request-forgery vulnerability and a security-bypass vulnerability.
Exploiting these issues could allow a remote attacker to perform certain administrative actions, bypass certain security restrictions, gain unauthorized access to the affected device, or delete certain data. Other attacks are also possible.
NETGEAR Wireless Cable Modem Gateway CG814WG 3.9.26 R14 is vulnerable; other versions may also be affected.
NETGEAR Wireless Cable Modem Gateway is prone to a cross-site request-forgery vulnerability and a security-bypass vulnerability.
Exploiting these issues could allow a remote attacker to perform certain administrative actions, bypass certain security restrictions, gain unauthorized access to the affected device, or delete certain data. Other attacks are also possible.
NETGEAR Wireless Cable Modem Gateway CG814WG 3.9.26 R14 is vulnerable; other versions may also be affected.
Exploit / POC
NETGEAR Wireless Cable Modem Gateway Cross Site Request Forgery and Security Bypass Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can use a browser to exploit these issues. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
NETGEAR Wireless Cable Modem Gateway Cross Site Request Forgery and Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
NETGEAR Wireless Cable Modem Gateway Cross Site Request Forgery and Security Bypass Vulnerabilities
References:
References:
- Netgear Homepage (NetGear)
- NETGEAR Wireless Cable Modem Gateway Auth Bypass and CSRF - SOS-11-011 (Sense of Security Labs)