vendor:
ReadyNAS
by:
Craig Young, hdm, juan vazquez
7,5
CVSS
HIGH
Code Injection
78
CWE
Product Name: ReadyNAS
Affected Version From: 4.1.11
Affected Version To: 4.2.23
Patch Exists: YES
Related CWE: CVE-2013-2751
CPE: o:netgear:readynas_4.2.23
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2013
NETGEAR ReadyNAS Perl Code Evaluation
This module exploits a Perl code injection on NETGEAR ReadyNAS 4.2.23 and 4.1.11. The vulnerability exists on the web fronted, specifically on the np_handler.pl component, due to the insecure usage of the eval() perl function. This module has been tested successfully on a NETGEAR ReadyNAS 4.2.23 Firmware emulated environment, not on real hardware.
Mitigation:
Apply the patch provided by NETGEAR.