8.3
CVSSv2

CVE-2014-2969

Published: 07/07/2014 Updated: 07/07/2014
CVSS v2 Base Score: 8.3 | Impact Score: 10 | Exploitability Score: 6.5
VMScore: 739
Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote malicious users to upload firmware or read or modify memory contents, and consequently execute arbitrary code, via a request to (1) produce_burn.cgi, (2) register_debug.cgi, or (3) bootcode_update.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

netgear gs108pe_firmware 1.2.0.5

netgear gs108pe -