Menu
Information disclosure flaw exposes Netgear wireless routers to attacks

Information disclosure flaw exposes Netgear wireless routers to attacks

The vulnerability allows attackers to extract admin passwords and wireless network keys

Several wireless routers made by Netgear contain a vulnerability that allows unauthenticated attackers to extract sensitive information from the devices, including their administrator passwords and wireless network keys.

The vulnerability can be exploited over local area networks, as well as over the Internet if the devices are configured for remote administration and expose their Web interface externally.

Details about the vulnerability were published on the Full Disclosure mailing list last week, along with a proof-of-concept exploit. Peter Adkins, the researcher who found the flaw, claims that he contacted Netgear but that his attempts to explain the nature of the issue to the company's technical support department failed.

The vulnerability is located in a service designed to interact with Netgear Genie, an application that allows users to monitor and control their routers from their smartphones or PCs.

At first glance, sending requests to this SOAP (Simple Object Access Protocol) service requires an authenticated session. However, Adkins discovered that sending HTTP requests with a blank form and a "SOAPAction" header is enough to extract sensitive information from a vulnerable device.

The information that can be extracted includes the administrator password; the name and access keys for the wireless networks configured on the device, and details about the device including its model, serial number and firmware version.

Adkins confirmed that Netgear WNDR3700v4, WNDR3700v4, WNR2200 and WNR2500 devices are vulnerable. However, because of the flaw's location, other devices, including WNDR3800, WNDRMAC, WPN824N and WNDR4700, might also be affected, he said.

Netgear did not immediately respond to a request for comment.

Routers configured for remote administration are obviously at greater risk since attackers can target them over the Internet. However, LAN-based attacks are not hard to execute either.

Attackers could potentially exploit the vulnerability after infecting a computer on the local network with malware. They could also use cross-site request forgery (CSRF) techniques that involve tricking users into visiting a site that forces their browsers to forward a malicious request to their routers over their local networks. Guest wireless networks also become a risk factor with this type of vulnerability.

Adkins recommends disabling remote support and only allowing trusted devices on the local network.

Wireless routers are an attractive target for attackers because they allow them to manipulate traffic for entire networks and provide them with a foothold in those networks that is not easily discovered. Several large scale attacks exploiting router vulnerabilities have been reported over the past two years.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags intrusionsecurityAccess control and authenticationnetgearExploits / vulnerabilities

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments