Blog | G5 Cyber Security

Netgear Root Compromise via Command Injection

The Netgear wndr3700v4’s authentication bugs have been exposed. Once the web interface is unlocked, any bugs that normally require authentication become fair game. I’ve written up some proof-of-concept exploit code that will access this page and start up a telnet server, allowing you to log in unauthenticated as root. The exploit code does the following:Fingerprint the device to ensure it’s vulnerable.Disable authentication. Re-enable authentication, restore the device’s original state.”]

Source: https://shadow-file.blogspot.com/2013/10/netgear-root-compromise-via-command.html

Exit mobile version