NETGEAR FM114P ProSafe Router Multiple Vulnerabilities

This script is Copyright (C) 2003-2014 Tenable Network Security, Inc.

Synopsis :

The remote service is subject to an information disclosure flaw.

Description :

The NETGEAR FM114P ProSafe Wireless Router (and possibly other devices)
discloses the username and password of the WAN when it receives specially
crafted UPnP soap requests.

An attacker may use this flaw to steal a valid username and password.

In addition to this, an attacker may use UPnP to disable the firewall
rules of that device, thus bypassing the security policy that has been

See also :

Solution :

Reconfigure the device to disable remote management or UPnP.

Risk factor :

High / CVSS Base Score : 7.5
CVSS Temporal Score : 7.5
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 11514 ()

Bugtraq ID: 7267