vendor:
Netgear DG632 Router
by:
Tom Neaves
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: Netgear DG632 Router
Affected Version From: Firmware V3.4.0_ap
Affected Version To: Firmware V3.4.0_ap
Patch Exists: NO
Related CWE: N/A
CPE: h:netgear:dg632
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
Netgear DG632 Router Remote DoS Vulnerability
The Netgear DG632 router has a web interface which runs on port 80. This allows an admin to login and administer the device's settings. However, a Denial of Service (DoS) vulnerability exists that causes the web interface to crash and stop responding to further requests. Within the "/cgi-bin/" directory of the administrative web interface exists a file called "firmwarecfg". This file is used for firmware upgrades. A HTTP POST request for this file causes the web server to hang. The web server will stop responding to requests and the administrative interface will become inaccessible until the router is physically restarted.
Mitigation:
Disable the "Remote Management" feature on the router.