5
CVSSv2

CVE-2016-5649

Published: 24/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote malicious user to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgear dgn2200 firmware 1.0.0.50 7.0.50

netgear dgnd3700 firmware 1.0.0.17 1.0.17

Exploits

Netgear DGN2200 and DGND3700 proof of concept administrative password disclosure exploit ...