"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards - and even then I have my doubts. - Gene Spafford"
HIO-2009-0521 Netgear RP614v4 CSRF & XSS PDF Print E-mail

The Netgear RP614v4 Broadband Router exhibits a vulnerabilities which can be exploited by malicious people to conduct cross-site request forgery attacks and cross-site scripting attacks.

1) The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. perform all administrative actions by enticing a logged-in administrator to visit a malicious site.

2) Script submitted to /cgi-gin/apply via the AddKeyword variable becomes persistent (script insertion) when submitted by enticing a logged-in administrator to visit a malicious site.

The vulnerability is reported in hardware version 4 and firmware version 1.0.5_04.23. Other versions may also be affected.

References:

CVE-2009-pending

BID: 35214

VUPEN: 

Nessus:N/A

OSVDB: 

SA: 35276  

XF: 

Related: 

Vendor Solution:


 
< Prev   Next >