vendor:
WNR1000v4
by:
Daniel Haake
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: WNR1000v4
Affected Version From: N300 router firmware versions 1.1.0.24
Affected Version To: N300 router firmware versions 1.1.0.31
Patch Exists: YES
Related CWE: requested
CPE: h:netgear:wnr1000v4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Can be exploited using a browser
2015
Netgear_WNR1000v4_AuthBypass
Multiple NETGEAR wireless routers are out of the box vulnerable to an authentication bypass attack. No router options has to be changed to exploit the issue. So an attacker can access the administration interface of the router without submitting any valid username and password, just by requesting a special URL several times.
Mitigation:
Ensure that authentication is enabled on the router and that strong passwords are used.