Collected research
Zach Cutlip -- Remote Code Execution in Netgear routers
Some Netgear Routers Open to Remote Authentication Bypass, Command Injection
Zach Cutlip found a command injection in the Netgear WNDR3700v4: cmd_ping6() sprintf()s an attacker-supplied host into a shell string passed to system(), so "; evil_command; #" runs as root. Chained with his separate /BRS_02_genieHelp.html bypass, which disables admin authentication across reboots, it gives unauthenticated root on firmware 1.0.1.32 and 1.0.1.42.
Record
- Document
- Some Netgear Routers Open to Remote Authentication Bypass, Command Injection
- Researcher
- Dennis Fisher
- Published by
- Threatpost | The first stop for security news
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Dennis Fisher, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .