WPS PIN Exposure (CVE‐2024‐36792) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki

Description:

An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

Impact:

NETGEAR WNR614 router stores sensitive authentication credentials in cleartext, risking unauthorized access, router manipulation, and potential data exposure. Immediate action is essential for remediation.

Mitigation:

  • Disable WPS functionality to prevent this attack vector.
  • Use WPA3 for better security if supported.
  • Regularly monitor and disable the WPS setting.

POC:

NETGEAR routers flawed WPS implementation creates a security loophole that could lead to unauthorized network access and setting manipulation.

image Figure: WPS PIN Exposure