NetGear WNDR Authentication Bypass / Information Disclosure

Posted by Peter Adkins on Feb 13

Reported by:
—-
Peter Adkins <peter.adkins () kernelpicnic.net>

Access:
—-
Local network; unauthenticated access.
Remote network; unauthenticated access*.

Tracking and identifiers:
—-
CVE – Mitre contacted; not yet allocated.

Platforms / Firmware confirmed affected:
—-
NetGear WNDR3700v4 – V1.0.0.4SH
NetGear WNDR3700v4 – V1.0.1.52
NetGear WNR2200 – V1.0.1.88
NetGear WNR2500 – V1.0.0.24

Additional platforms believed to be…