PT-2017-7964 · NetGear · Wndap360+5
Dominic Chen
·
Published
2017-04-21
·
Updated
2017-04-28
·
CVE-2016-1556
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Netgear WN604 versions prior to 3.3.3
Netgear WNAP210 versions prior to 3.5.5.0
Netgear WNAP320 versions prior to 3.5.5.0
Netgear WNDAP350 versions prior to 3.5.5.0
Netgear WNDAP360 versions prior to 3.5.5.0
Netgear WND930 versions prior to 2.0.11
Description
The issue allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages, leading to information disclosure.
Recommendations
For Netgear WN604 versions prior to 3.3.3, update to version 3.3.3 or later.
For Netgear WNAP210 versions prior to 3.5.5.0, update to version 3.5.5.0 or later.
For Netgear WNAP320 versions prior to 3.5.5.0, update to version 3.5.5.0 or later.
For Netgear WNDAP350 versions prior to 3.5.5.0, update to version 3.5.5.0 or later.
For Netgear WNDAP360 versions prior to 3.5.5.0, update to version 3.5.5.0 or later.
For Netgear WND930 versions prior to 2.0.11, update to version 2.0.11 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wn604
Wnap210
Wnap320
Wnd930
Wndap350
Wndap360