How to Buy
This script is Copyright (C) 2006-2013 Tenable Network Security, Inc.
The remote router allows anonymous users to retrieve the administrative password
The remote host appears to be running a Netopia router with SNMP enabled.
Further, the Netopia router is using the default SNMP community strings.
This version of the Netopia firmware is vulnerable to a flaw wherein
a remote attacker can, by sending a specially formed SNMP query, retrieve
the Administrative password.
An attacker, exploiting this flaw, would only need to be able to send SNMP
queries to the router using the default community string of 'public'.
Successful exploitation would result in the attacker gaining administrative
credentials to the router.
See also :
Contact the vendor for a patch. Change the default SNMP community string to
one that is not easily guessed.
Risk factor :
Critical / CVSS Base Score : 10.0
Nessus Plugin ID: 22415 ()
Nessus Professional: Scan unlimited IPs, run compliance checks & moreNessus Cloud: The power of Nessus for teams – from the cloud
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.