NETGEAR FM114P ProSafe Router Multiple Vulnerabilities
High Nessus Plugin ID 11514
SynopsisThe remote service is subject to an information disclosure flaw.
DescriptionThe NETGEAR FM114P ProSafe Wireless Router (and possibly other devices) discloses the username and password of the WAN when it receives specially crafted UPnP soap requests.
An attacker may use this flaw to steal a valid username and password.
In addition to this, an attacker may use UPnP to disable the firewall rules of that device, thus bypassing the security policy that has been set.
SolutionReconfigure the device to disable remote management or UPnP.