vendor:
ADSL Router
by:
Todor Donev
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: ADSL Router
Affected Version From: 1.0.7.2 / 1.0.0.9 / 1.0.0.32 / 1.0.0.20
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Authenticated Remote File Disclosure
This vulnerability allows an attacker to bypass authentication and access sensitive files on NETGEAR ADSL routers. The vulnerability exists in the webproc CGI script, which allows an attacker to access the /etc/shadow file without authentication. This can be exploited by sending a specially crafted HTTP request to the vulnerable router.
Mitigation:
Upgrade to the latest version of the firmware.