vendor:
ProSafe
by:
Juan J. Guelfo
9,3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ProSafe
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2013-4775
CPE: h:netgear:prosafe
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Netgear ProSafe – CVE-2013-4775 PoC
This PoC exploit allows an attacker to remotely execute code on a vulnerable Netgear ProSafe device. The exploit is triggered by sending a specially crafted HTTP request to the device's web interface. The request contains a malicious payload which is then executed on the device.
Mitigation:
The vendor has released a patch to address this vulnerability.