vendor:
SSL312 router
by:
Rembrandt
7.5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: SSL312 router
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Netgear embedded Linux
2008
Netgear VPN router SSL312 Remote DoS Vulnerability
Netgear VPN router SSL312 is proune to a remote DoS condition which can get triggered if somebody has access to the webinterface of the VPN router. The problem is related to a propietary CGI binary and makes is impossible for users to patch the router. If you modify the URL as below and resend your http request the device will crash and reboot.
Mitigation:
Contacting Netgear and mitre.org