Netgear Authentication Bypass Allows Router Takeover
#1
Information 
Quote:Netgear has patched three bugs in one of its router families that, if exploited, can allow threat actors to bypass authentication to breach corporate networks and steal data and credentials.
 
Microsoft security researchers discovered the bugs in Netgear DGN-2200v1 series routers while they were researching device fingerprinting, Microsoft 365 Defender research team’s Jonathan Bar Or said in a blog post, posted Wednesday.
 
“We noticed a very odd behavior: A device owned by a non-IT personnel was trying to access a Netgear DGN-2200v1 router’s management port,” researchers wrote.
 
Researchers investigated and eventually identified the vulnerabilities, tracked as PSV-2020-0363, PSV-2020-0364 and PSV-2020-0365 by Netgear (CVEs were not issued), and which range in CVSS rating from high (7.4) to critical (9.4). They reported their discovery to Netgear, which has released a security advisory patching the flaws.
 
An attacker can exploit the flaws to breach a router’s management pages without having to log in, and take over the router, as well as use a cryptographic side-channel attack to acquire the router’s saved credentials, Bar wrote.
 
Full exploitation of the vulnerabilities “can compromise a network’s security — opening the gates for attackers to roam untethered through an entire organization,” he wrote.

Read more: Netgear Authentication Bypass Allows Router Takeover | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Privazer 4.0.19
PrivaZer version v...Kool — 11:15
XYplorer
What's new in Rele...Kool — 11:11
QOwnNotes
25.8.7 In the l...Kool — 11:08
QOwnNotes
25.8.6 When ent...Kool — 13:43
Adguard for Windows, Android, iOS
AdGuard for Window...Kool — 10:43

[-]
Birthdays
Today's Birthdays
avatar (49)DavidDow
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (40)obudyg
avatar (48)rarinsWax
avatar (25)DianaBrown
avatar (35)emyzowa
avatar (46)JustinPrede
avatar (38)eqiduseb
avatar (44)fedosmiday
avatar (41)brechTiz
avatar (47)schedZoorb
avatar (41)bgreorasjunior4824
avatar (45)ThomasLYDAY
avatar (40)upakoExapy
avatar (39)Margieweimi
avatar (39)Larondabet
avatar ()tradedeer1
avatar (50)diplomasync
avatar (49)Myronjax
avatar (49)skepwHug
avatar (38)RicardoGoase
avatar (41)JaniceArods
avatar (42)Brianven
avatar (31)I3rYcE
avatar (42)Edwardgef
avatar (43)Denpokhew
avatar (35)azidony
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>