Password Policy Bypass (CVE‐2024‐36789) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki

Description:

An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards

Impact:

Netgear WNR614 router vulnerability allows insecure passwords, risking unauthorized access, network manipulation, and potential data exposure.

Mitigation:

  • Implement a strong password policy and enforce it rigorously.
  • Use third-party security software to manage and enforce password policies.
  • Regularly audit passwords and access controls.

POC:

Users can bypass Netgear's password policies by setting a single-digit password on the WNR614 router.

image Figure: Password Policy Bypass