Skip to content
View in the app

A better way to browse. Learn more.

Thailand News and Discussion Forum | ASEANNOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

NetGear WNDR Authentication Bypass Vulnerability

Featured Replies

A vulnerability exists in a number of Netgear routers whereby a remote user can bypass authentication.

Known and suspect models can be found on the following site together with details of the vulnerability. http://www.securitytracker.com/id/1031762

See this Wikipedia article for an explanation of SOAP: http://en.wikipedia.org/wiki/SOAP

No fix was available at the time of writing.

Workaround: disable remote / WAN management.

kristoffer.png

Sound like Netgear needs to hire 5-year-old Kristoffer to do product vulnerability testing.

"At first glance, this service [sOAP / NetGear Genie application ] appears to be filtered and authenticated;
HTTP requests with a `SOAPAction` header set but without a session identifier will yield a HTTP 401 error. However, a HTTP request with a
blank form and a `SOAPAction` header is sufficient to execute certain requests and query information from the device."
Yep, Kristoffer would have found this vulnerability with his 'blank' and 'multiple spaces as a valid entry' routine.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.