header-logo
Suggest Exploit
vendor:
WNR2000
by:
SecurityFocus
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: WNR2000
Affected Version From: 1.2.0.8
Affected Version To: 1.2.0.8
Patch Exists: YES
Related CWE: N/A
CPE: h:netgear:wnr2000
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

NetGear WNR2000 Remote Information Disclosure Vulnerability

The NetGear WNR2000 is prone to multiple remote information-disclosure issues because it fails to restrict access to sensitive information. A remote attacker can exploit these issues to obtain sensitive information, possibly aiding in further attacks. Information obtained in attacks may be used in exploits targeting the vulnerability covered in BID 36094 (NetGear WNR2000 'upg_restore.cgi' Authentication Bypass Vulnerability).

Mitigation:

Restrict access to sensitive information.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/36076/info

The NetGear WNR2000 is prone to multiple remote information-disclosure issues because it fails to restrict access to sensitive information.

A remote attacker exploit these issues to obtain sensitive information, possibly aiding in further attacks.

NOTE: Information obtained in attacks may be used in exploits targeting the vulnerability covered in BID 36094 (NetGear WNR2000 'upg_restore.cgi' Authentication Bypass Vulnerability).

The WNR2000 with firmware 1.2.0.8 is vulnerable; other firmware versions may also be affected. 

The following example URIs are available:

http://www.example.com/router-info.htm
http://www.example.com/cgi-bin/router-info.htm
http://www.example.com/cgi-bin/NETGEAR_WNR2000.cfg