Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Trevor Seward

#21004of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2011-3284
5.0
2011-04-10
NetGear · Netgear Prosafe Wnap210 · CVE-2011-1673
**Name of the Vulnerable Software and Affected Versions** NetGear ProSafe WNAP210 (affected versions not specified) **Description** The issue allows remote attackers to obtain the administrator password by reading the configuration file `BackupConfig.php`. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2011-3285
6.8
2011-04-10
NetGear · Netgear Prosafe Wnap210 · CVE-2011-1674
**Name of the Vulnerable Software and Affected Versions** NetGear ProSafe WNAP210 version 2.0.12 **Description** The issue allows remote attackers to bypass authentication and obtain access to the configuration page. This can be achieved by visiting the "recreate.php" endpoint and then accessing the "index.php" endpoint. **Recommendations** For NetGear ProSafe WNAP210 version 2.0.12, consider restricting access to the "recreate.php" and "index.php" endpoints until a patch is available. As a temporary workaround, limit the exposure of the device to the internet and only allow trusted sources to access the configuration page.