Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.809775
Category:Web application abuses
Title:NETGEAR WNR2000 Router Multiple Vulnerabilities (Dec 2016) - Active Check
Summary:NETGEAR WNR2000 Router devices are prone to multiple; vulnerabilities.
Description:Summary:
NETGEAR WNR2000 Router devices are prone to multiple
vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- The device leaks its serial number while requesting for
'BRS_netgear_success.html'.

- Improper access control while sending request to 'apply_noauth.cgi'.

- Timestamps used in application can be easily calculated and generated outside.

- Improper handling of access to *.cgi files by HTTP server in the device (uhttpd).

Vulnerability Impact:
Successful exploitation will allow remote
attackers to gain access to potentially sensitive information, reboot router,
factory reset the router, change WLAN settings, change password recovery settings,
obtain the admin password once recovery settings are changed, execute code and
conduct denial of service attack.

Affected Software/OS:
NETGEAR WNR2000 routers.

Solution:
NETGEAR has released beta firmware for the affected routers,
which can be obtained from the referenced vendor KB entry.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-10175
BugTraq ID: 95867
http://www.securityfocus.com/bid/95867
https://www.exploit-db.com/exploits/40949/
http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability
http://seclists.org/fulldisclosure/2016/Dec/72
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt
Common Vulnerability Exposure (CVE) ID: CVE-2016-10176
Common Vulnerability Exposure (CVE) ID: CVE-2016-10174
https://www.exploit-db.com/exploits/41719/
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.