vendor:
DD-WRT
by:
Craig Heffner
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: DD-WRT
Affected Version From: v24-preSP2
Affected Version To: v24-preSP2
Patch Exists: NO
Related CWE: N/A
CPE: a:dd-wrt:dd-wrt
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Builds 14311, 14896
2010
DD-WRT Information Disclosure Vulnerability
Remote attackers can gain sensitive information about a DD-WRT router and internal clients, including IP addresses, MAC addresses and host names. This information can be used for further network attacks as well as very accurate MAC address geolocation. This is exploitable even if remote administration is disabled.
Mitigation:
Users should enable remote administration and set the info page to 'enabled with authentication' in order to prevent remote users from obtaining this information without first authenticating to the router.