CVE-2016-5649
Netgear DGN2200 and DGND3700 disclose the administrator password
Record summary
CVE-2016-5649 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DGN2200Browse Netgear / DGN2200 | CVE List | DGN2200-V1.0.0.50_7.0.50 | affected |
DGND3700Browse Netgear / DGND3700 | CVE List | DGND3700-V1.0.0.17_1.0.17 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALNETGEAR DGN2200 / DGND3700 - Admin Password DisclosureCVSS 9.8
NETGEAR DGN2200 / DGND3700 is susceptible to a vulnerability within the page 'BSW_cxttongr.htm' which can allow a remote attacker to access this page without any authentication. The attacker can then use this password to gain administrator access of the targeted router's web interface.
Impact
An attacker can obtain the admin password and gain unauthorized access to the router's settings, potentially leading to further compromise of the network.
Remediation
Update the router firmware to the latest version, which includes a fix for the vulnerability.
Source: ProjectDiscovery