Описание
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-0408
- https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/ex2800
- https://www.netgear.com/support/product/ex3110
- https://www.netgear.com/support/product/ex5000
- https://www.netgear.com/support/product/ex6110
Связанные уязвимости
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
Уязвимость графического интерфейса микропрограммного обеспечения сетевого оборудования Netgear WiFi Range Extenders, связанная с недостатками процедуры аутентификации, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации