Improper Authentication Broken Access Control (CVE‐2024‐36787) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki

Description:

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

Impact:

Poor authentication protocols allowing insecure passwords pose a severe threat to network security, necessitating immediate and decisive action to stop unauthorized access and protect network operations and sensitive data.

Mitigation:

  • Immediately disable remote management to minimize the risk of unauthorized access.
  • Use strong, complex passwords and change them regularly.
  • Establish network segmentation to separate your router from vital systems.

POC:

The Netgear WNR614 router’s weak authentication, allowing Base64 credential cracking, poses a serious security risk.

image

Figure: Improper Authentication

image

Figure: Broken Access Control