[] NeoSense

Netgear WNR2000 - Multiple Information Disclosure Vulnerabilities

Author: Jean Trolleur
type: remote
platform: hardware
port: 
date_added: 2009-08-18 
date_updated: 2014-05-04 
verified: 1 
codes: OSVDB-57420 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/36076/info

The NetGear WNR2000 is prone to multiple remote information-disclosure issues because it fails to restrict access to sensitive information.

A remote attacker exploit these issues to obtain sensitive information, possibly aiding in further attacks.

NOTE: Information obtained in attacks may be used in exploits targeting the vulnerability covered in BID 36094 (NetGear WNR2000 'upg_restore.cgi' Authentication Bypass Vulnerability).

The WNR2000 with firmware 1.2.0.8 is vulnerable; other firmware versions may also be affected.

The following example URIs are available:

http://www.example.com/router-info.htm
http://www.example.com/cgi-bin/router-info.htm
http://www.example.com/cgi-bin/NETGEAR_WNR2000.cfg