NetGore: Simple Flaw Affects Hundreds of Thousands of Netgear Devices
ID: bcea89b8-e74b-5208-a150-3f8e648bf32d
STIX ID: report--bcea89b8-e74b-5208-a150-3f8e648bf32d
Feed Name: Security Ledger
Trustwave disclosed an authentication-bypass vulnerability in over 30 Netgear SOHO router models that can leak administrative passwords via a password-recovery token; the flaw is trivial to exploit by local users or remotely if remote management is enabled, impacts thousands to potentially hundreds of thousands of devices, and enables attacker control (including DNS hijacking). Netgear has released firmware updates for some models and recommended mitigations for others, but several affected models remain without patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
