PT-2024-4671 · NetGear · Netgear Wnr614
Published
2024-05-30
·
Updated
2024-08-22
·
CVE-2024-36795
CVSS v2.0
5.2
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Netgear WNR614 version JNR1010V2/N300-V1.1.0.54 1.0.1
Description:
The issue is related to insecure permissions in the Netgear WNR614 router's firmware, which can allow attackers to access URLs and directories embedded within the firmware via unspecified vectors. This can potentially lead to unauthorized access to protected information.
Recommendations:
For version JNR1010V2/N300-V1.1.0.54 1.0.1, consider restricting access to the firmware's embedded URLs and directories until a patch is available. As a temporary workaround, limit the exposure of the router to the internet and avoid using it for sensitive operations. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear Wnr614