Web Hack List

Collected research

Zach Cutlip -- Remote Code Execution in Netgear routers

Some Netgear Routers Open to Remote Authentication Bypass, Command Injection

Zach Cutlip found a command injection in the Netgear WNDR3700v4: cmd_ping6() sprintf()s an attacker-supplied host into a shell string passed to system(), so "; evil_command; #" runs as root. Chained with his separate /BRS_02_genieHelp.html bypass, which disables admin authentication across reboots, it gives unauthenticated root on firmware 1.0.1.32 and 1.0.1.42.

Record

Document
Some Netgear Routers Open to Remote Authentication Bypass, Command Injection
Researcher
Dennis Fisher
Published by
Threatpost | The first stop for security news
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Dennis Fisher, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .