WPS PIN Exposure (CVE‐2024‐36792) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki
Description:
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
Impact:
NETGEAR WNR614 router stores sensitive authentication credentials in cleartext, risking unauthorized access, router manipulation, and potential data exposure. Immediate action is essential for remediation.
Mitigation:
- Disable WPS functionality to prevent this attack vector.
- Use WPA3 for better security if supported.
- Regularly monitor and disable the WPS setting.
POC:
NETGEAR routers flawed WPS implementation creates a security loophole that could lead to unauthorized network access and setting manipulation.
Figure: WPS PIN Exposure