A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.
The vulnerability is due to improper authentication implementation (CWE-287) in the component handling the /BRS_top.html file. This resource is accessible without required authentication, allowing an attacker to bypass the Basic Authentication mechanism. The attack can be conducted remotely over the network, without user interaction and without any prior privileges. The exploit has been made public and may be actively exploited.
An attacker can gain unauthorized access to protected device resources, threatening the confidentiality, integrity, and availability of the system. This could lead to takeover of the router and modification of its configuration.
Patches available from the manufacturer should be applied according to the references. It is recommended to monitor official Netgear security communications at https://www.netgear.com/. Until a patch is released, it is recommended to restrict access to the device management interface through a firewall or network segmentation.
Netgear DGND3700 with firmware version 1.1.00.15_1.00.15NA. According to manufacturer information, other Netgear products may also be affected.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNetgear Dgnd3700
HWNetgearv2Netgear Dgnd3700 Firmware
OSNetgear1.1.00.15_1.00.15na
Related vulnerabilities
Ominięcie uwierzytelnienia w urządzeniach NETGEAR via manipulacja URL
Netgear DGN2200/DGND3700 — ujawnienie hasła admina w postaci jawnego tekstu
Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before...
A vulnerability, which was classified as problematic, has been found in Netgear DGND3700 1.1.00.15_1.00.15NA. ...
A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vul...