PT-2017-7785 · NetGear · Netgear Wnr2000V5
Pedro Ribeiro
·
Published
2017-01-30
·
Updated
2017-09-03
·
CVE-2016-10176
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR WNR2000v5 router
Description
The issue allows an unauthenticated user to perform sensitive actions on the device by invoking a specific URL on the web server. This can be exploited to change router settings, such as password-recovery questions, and achieve remote code execution. The embedded web server (uhttpd) handles the apply.cgi and apply noauth.cgi URLs, with the latter allowing unauthorized access to perform these actions.
Recommendations
For the NETGEAR WNR2000v5 router, consider restricting access to the apply noauth.cgi URL as a temporary workaround until a patch is available. Avoid using the apply noauth.cgi URL in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Wnr2000V5