vendor:
ReadyNAS LAN
by:
St0rn
7.5
CVSS
HIGH
Credential Stealing
522
CWE
Product Name: ReadyNAS LAN
Affected Version From: Firmware 6.2.4
Affected Version To: Firmware 6.2.4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
NETGEAR ReadyNAS LAN /dbbroker Credential Stealing
NETGEAR ReadyNAS LAN /dbbroker Credential Stealing is a vulnerability that allows an attacker to steal credentials from a NETGEAR ReadyNAS LAN device. The exploit uses scapy to sniff the network traffic and extract the credentials from the POST request sent to the dbbroker. The credentials are then decoded from base64 and printed to the screen.
Mitigation:
Users should ensure that their NETGEAR ReadyNAS LAN devices are running the latest firmware version and that all security patches are applied.