NETGEAR FM114P ProSafe Router Multiple Vulnerabilities

This script is Copyright (C) 2003-2011 Tenable Network Security, Inc.


Synopsis :

The remote service is subject to an information disclosure flaw.

Description :

The NETGEAR FM114P ProSafe Wireless Router (and possibly other devices)
discloses the username and password of the WAN when it receives specially
crafted UPnP soap requests.

An attacker may use this flaw to steal a valid username and password.

In additition to this, an attacker may use UPnP to disable the firewall
rules of that device, thus bypassing the security policy that has been
set.

See also :

http://archives.neohapsis.com/archives/bugtraq/2003-04/0042.html
http://archives.neohapsis.com/archives/bugtraq/2003-04/0053.html

Solution :

Reconfigure the device to disable remote management or UPnP.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 7.5
(CVSS2#E:H/RL:U/RC:ND)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 11514 ()

Bugtraq ID: 7267
7270

CVE ID: