CVE-2016-5649
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.
- Affected products
- Netgear Dgn2200, Netgear Dgnd3700
- Netgear dgn2200 Firmware
- = 1.0.0.50_7.0.50
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 27.2% (98th percentile)
- Weakness
- CWE-200, CWE-319
- NVD status
- Modified
- Published
- 2018-07-24
Fix
Netgear has released firmware version 1.0.0.52 for DGN2200 & 1.0.0.28 for DGND3700 to address this issue.
CVE-2016-5649 at NVD
5 known exploits for CVE-2016-5649
Proof-of-concept code and exploit modules indexed by Sploitus
Netgear DGN2200 / DGND3700 - Admin Password Disclosure Vulnerability
Netgear DGN2200 DGND3700 - Admin Password Disclosure
Netgear DGN2200 / DGND3700 - Admin Password Disclosure
Netgear DGN2200 / DGND3700 Admin Password Disclosure
Netgear DGN2200 / DGND3700 / WNDR4500 Information Disclosure Vulnerability