vendor:
WMS5316 ProSafe 16AP Wireless Management System
by:
Reinforce Services
8,8
CVSS
HIGH
Authentication Bypass and Privilege Escalation
287
CWE
Product Name: WMS5316 ProSafe 16AP Wireless Management System
Affected Version From: Firmware 2.1.4.15 (Build 1236)
Affected Version To: Firmware 2.1.4.15 (Build 1236)
Patch Exists: YES
Related CWE: Not assigned
CPE: h:netgear:wms5316_prosafe_16ap_wireless_management_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
NETGEAR Wireless Management System – Authentication Bypass and Privilege Escalation
The process to bypass authentication and escalate privileges is as follows: Include the '&' symbol anywhere in the password value in the login request (as raw content - it must not be encoded). After a moment, the system will accecpt the login request and return a valid session cookie. Using the valid session cookie, send a request to add a new user with administrative privileges.
Mitigation:
Upgrade to the latest version of the firmware (2.1.5)