{ "CVE_data_meta": { "ASSIGNER": "cert@cert.org", "ID": "CVE-2016-5649", "STATE": "PUBLIC", "TITLE": "Netgear DGN2200 and DGND3700 disclose the administrator password" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "DGN2200", "version": { "version_data": [ { "affected": "=", "version_name": "DGN2200-V1.0.0.50_7.0.50", "version_value": "DGN2200-V1.0.0.50_7.0.50" } ] } }, { "product_name": "DGND3700", "version": { "version_data": [ { "affected": "=", "version_name": "DGND3700-V1.0.0.17_1.0.17", "version_value": "DGND3700-V1.0.0.17_1.0.17" } ] } } ] }, "vendor_name": "Netgear" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-319" } ] } ] }, "references": { "reference_data": [ { "name": "https://packetstormsecurity.com/files/140342/Netgear-DGN2200-DGND3700-WNDR4500-Information-Disclosure.html", "refsource": "MISC", "url": "https://packetstormsecurity.com/files/140342/Netgear-DGN2200-DGND3700-WNDR4500-Information-Disclosure.html" }, { "refsource": "MISC", "name": "http://packetstormsecurity.com/files/152675/Netgear-DGN2200-DGND3700-Admin-Password-Disclosure.html", "url": "http://packetstormsecurity.com/files/152675/Netgear-DGN2200-DGND3700-Admin-Password-Disclosure.html" } ] }, "solution": [ { "lang": "eng", "value": "Netgear has released firmware version 1.0.0.52 for DGN2200 & 1.0.0.28 for DGND3700 to address this issue." } ], "source": { "discovery": "UNKNOWN" } }