Insecure Permissions (CVE‐2024‐36795) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki
Description:
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.
Impact:
The unencrypted storage of sensitive data, like mail server credentials, in NETGEAR router firmware, significantly heightens the risk of unauthorized network access.
Mitigation:
Implement access control measures to restrict access to the router's administrative interface. Encrypt sensitive data stored on the router.
POC:
Exploiting these vulnerabilities could allow attackers to access sensitive data and control router settings, threatening network security and necessitating urgent protective measures.
Figure: Insecure Permissions