header-logo
Suggest Exploit
vendor:
WGR614v9 Wireless Router
by:
Fabrizio Siciliano (staticrez)
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: WGR614v9 Wireless Router
Affected Version From: v1.2.2_14.0.13NA
Affected Version To: WNR834Bv2 v2.0.8_2.0.8
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Denial of Service condition in Netgear’s WGR614v9 Wireless Router

Appending a question mark to the router's internal IP address after the forward slash. e.g., http://192.168.1.1/? results in a denial of service condition where the http server dies and the administrative interface is no longer available until after a device reboot.

Mitigation:

Ensure that the router's internal IP address is not accessible from the internet.
Source

Exploit-DB raw data:

LUNOSEC ADVISORY

Synopsis: Denial of Service condition in Netgear's WGR614v9 Wireless Router

Firmware version tested: v1.2.2_14.0.13NA (LATEST)
Firmware version tested: WNR834Bv2 v2.0.8_2.0.8 # GTADarkDude tested

Proof of Concept:

Appending a question mark to the router's internal IP address after
the forward slash. e.g., http://192.168.1.1/? results in a denial of
service condition where the http server dies and the administrative
interface is no longer available until after a device reboot.

found: fabrizio siciliano (staticrez)

# milw0rm.com [2009-02-25]