漏洞描述 Netgear 路由器多版本管理后台downloadFile.php接口处存在信息泄露漏洞,未经身份验证的远程攻击者可以利用此漏洞获取无线路由器的管理员账号密码信息,导致路由器后台被控,攻击者可对无线网络发起破坏或进一步威胁。
相关漏洞推荐 POC CVE-2016-1555: NETGEAR WNAP320 Access Point Firmware - Remote Command Injection POC CVE-2016-5649: NETGEAR DGN2200 / DGND3700 - Admin Password Disclosure POC CVE-2016-6277: NETGEAR Routers - Remote Code Execution POC CVE-2017-5521: NETGEAR Routers - Authentication Bypass POC CVE-2020-26919: NETGEAR ProSAFE Plus - Unauthenticated Remote Code Execution POC CVE-2020-27866: NETGEAR - Authentication Bypass POC CVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun POC CVE-2022-29383: NETGEAR ProSafe SSL VPN firmware - SQL Injection POC CVE-2024-30568: Netgear R6850 V1.1.0.88 - Command Injection POC CVE-2024-30569: Netgear R6850 - Information Disclosure POC CVE-2024-30570: Netgear R6850 - Information Disclosure POC CVE-2024-57046: Netgear DGN2200 - Improper Authentication POC CVE-2024-6646: Netgear-WN604 downloadFile.php - Information Disclosure