vendor:
DGN2200
by:
Social Engineering Neo
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: DGN2200
Affected Version From: 1.0.0.0
Affected Version To: 1.0.0.51
Patch Exists: YES
Related CWE: CVE-2016-5649
CPE: h:netgear:dgn2200
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2016
PoC based on CVE-2016-5649
A vulnerability exists within the page 'BSW_cxttongr.htm' which can allow a remote attacker to access this page without any authentication. When the request is processed, it exposes the administrator password in clear text before getting redirected to 'absw_vfysucc.cgia'. An attacker can use this password to gain administrator access of the targeted routers web interface.
Mitigation:
Netgear has released firmware version 1.0.0.52 for DGN2200 & 1.0.0.28 for DGND3700 to address this issue.