Insecure Permissions (CVE‐2024‐36795) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki

Description:

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

Impact:

The unencrypted storage of sensitive data, like mail server credentials, in NETGEAR router firmware, significantly heightens the risk of unauthorized network access.

Mitigation:

Implement access control measures to restrict access to the router's administrative interface. Encrypt sensitive data stored on the router.

POC:

Exploiting these vulnerabilities could allow attackers to access sensitive data and control router settings, threatening network security and necessitating urgent protective measures.

image Figure: Insecure Permissions