Check If Your Netgear Router is also Vulnerable to this Password Bypass Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-5521 | Password Disclosure Flaw in NETGEAR R7000, R6400, R6700, R8500 and Other Routers NETGEAR routers across many popular models leak the admin password through a flaw in the web management interface's password recovery flow. When a visitor cancels the login prompt and password recovery is not enabled, the router exposes a password recovery token, and requesting /passwordrecovered.cgi?id=TOKEN with that token returns the router's admin password; the flaw is reachable remotely when the remote management option is enabled, and also from the LAN or WLAN. An attacker who obtains the password gains full administrative control of the router. Owners of the affected NETGEAR models are exposed, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08 with a public proof-of-concept available and an EPSS exploitation probability of ~89%, indicating active exploitation. Do: Apply firmware updates per NETGEAR's instructions; if an affected router has reached end-of-life, disconnect or replace it. As an interim mitigation, disable remote web management if it is not required, and note that enabling password recovery once (setting security questions) permanently blocks this exploit even if the option is later disabled. Administrators should check whether the web panel at /passwordrecovered.cgi exposes credentials when authentication is canceled. | 8.1 | 89% | KEV PoC |
| masshundreds of thousands to over 1 million internet-exposed NETGEAR routers |
Full article582 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalJan 31, 2017
Again bad news for consumers with Netgear routers: Netgear routers hit by another serious security vulnerability, but this time more than two dozens router models are affected.
Security researchers from Trustwave are warning of a new authentication vulnerability in at least 31 models of Netgear models that potentially affects over one million Netgear customers.
The new vulnerability, discovered by Trustwave's SpiderLabs researcher Simon Kenin, can allow remote hackers to obtain the admin password for the Netgear router through a flaw in the password recovery process.
Kenin discovered the flaw (CVE-2017-5521) when he was trying to access the management page of his Netgear router but had forgotten its password.
Exploiting the Bug to Take Full Access on Affected Routers
So, the researcher started looking for ways to hack his own router and found a couple of exploits from 2014 that he leveraged to discover this flaw which allowed him to query routers and retrieve their login credentials easily, giving him full access to the device.
But Kenin said the newly discovered flaw could be remotely exploited only if the router's remote management option is enabled.
While the router vendor claims the remote management option is turned off on its routers by default, according to the researcher, there are "hundreds of thousands, if not over a million" routers left remotely accessible.
"The vulnerability can be used by a remote attacker if remote administration is set to be internet facing. By default this is not turned on," Kenin said. "However, anyone with physical access to a network with a vulnerable router can exploit it locally. This would include public Wi-Fi spaces like cafés and libraries using the vulnerable equipment."
If exploited by bad actors, the vulnerability that completely bypasses any password on a Netgear router could give hackers complete control of the affected router, including the ability to change its configuration, turn it into botnets or even upload entirely new firmware.
After trying out his flaw on a range of Netgear routers, Kenin was surprised to know that more than ten thousand vulnerable devices used the flawed firmware and can be accessed remotely.
He has also released an exploit code for testing purpose, written in Python.
List of Vulnerable NETGEAR Router Models
The SpiderLabs researcher stressed that the vulnerability is very serious as it affects a large number of Netgear router models. Here's a list of affected Netgear routers:
- R8500
- R8300
- R7000
- R6400
- R7300DST
- R7100LG
- R6300v2
- WNDR3400v3
- WNR3500Lv2
- R6250
- R6700
- R6900
- R8000
- R7900
- WNDR4500v2
- R6200v2
- WNDR3400v2
- D6220
- D6400
- C6300 (firmware released to ISPs)
Update the Firmware of your NETGEAR Router Now!
Kenin notified Netgear of the flaw, and the company confirmed the issue affects a large number of its products.
Netgear has released firmware updates for all of its affected routers, and users are strongly advised to upgrade their devices.
This is the second time in around two months when researchers have discovered flaws in Netgear routers. Just last month, the US-CERT advised users to stop using Netgear's R7000 and R6400 routers due to a serious bug that permitted command injection.
However, in an effort to make its product safe, Netgear recently partnered up with Bugcrowd to launch a bug bounty program that can earn researchers cash rewards of up to $15,000 for finding and responsibly reporting flaws in its hardware, APIs, and the mobile apps.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2017/01/Netgear-router-password-hacking.html