Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2257. PoCs published by Tom Neaves.
AI-analyzed exploit summary This writeup describes an authentication bypass vulnerability in the Netgear DG632 router's web interface. The issue allows unauthenticated access to sensitive files by directly accessing them via their paths, bypassing the 'webcm' authentication script.
Description
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/.
Exploits (1)
This writeup describes an authentication bypass vulnerability in the Netgear DG632 router's web interface. The issue allows unauthenticated access to sensitive files by directly accessing them via their paths, bypassing the 'webcm' authentication script.