PT-2017-7785 · NetGear · Netgear Wnr2000V5

Pedro Ribeiro

·

Publicado

2017-01-30

·

Atualizado

2017-09-03

·

CVE-2016-10176

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR WNR2000v5 router
Description The issue allows an unauthenticated user to perform sensitive actions on the device by invoking a specific URL on the web server. This can be exploited to change router settings, such as password-recovery questions, and achieve remote code execution. The embedded web server (uhttpd) handles the apply.cgi and apply noauth.cgi URLs, with the latter allowing unauthorized access to perform these actions.
Recommendations For the NETGEAR WNR2000v5 router, consider restricting access to the apply noauth.cgi URL as a temporary workaround until a patch is available. Avoid using the apply noauth.cgi URL in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10176

Produtos afetados

Netgear Wnr2000V5