NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR Orbi 760 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SOAP API. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-20524.
oryginał ENCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNetgear Rbr760
HWNetgearwszystkie wersjeNetgear Rbr760 Firmware
OSNetgear< 6.3.8.5
Powiązane podatności
Luka ujawniania informacji w satelitach NETGEAR Orbi (seria RBR/RBE/RBS) mogłaby umożliwić użytkownikowi połąc...
Brak kontroli dostępu na poziomie funkcji w NETGEAR JGS516PE
Buffer overflow w routerach NETGEAR WNR2000 umożliwia RCE bez uwierzytelnienia
Command injection w firmwarze Netgear — zdalne wykonanie kodu
Command injection w NETGEAR DGN2200 przez ping.cgi