ID

VAR-200312-0517


TITLE

NetGear WAB102 Wireless Access Point Password Management Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2003-3581

DESCRIPTION

The NetGear WAB102 is a wireless access AP. The NetGear WAB102 has multiple password management issues that can be exploited by remote attackers to gain unauthorized access to the device for various malicious operations. An attacker can access the device by providing any password that contains spaces. Another problem is that the default password '1234' is reset when the device is powered down and reset. NetGear WAB102 running firmware version 1.2.3 has been reported to be prone to this issue

Trust: 0.81

sources: CNVD: CNVD-2003-3581 // BID: 9194

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2003-3581

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:netgearmodel:wab102 wireless access pointscope:eqversion:1.2.3

Trust: 0.3

sources: CNVD: CNVD-2003-3581 // BID: 9194

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2003-3581
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2003-3581
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2003-3581

THREAT TYPE

network

Trust: 0.3

sources: BID: 9194

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 9194

EXTERNAL IDS

db:BIDid:9194

Trust: 0.9

db:CNVDid:CNVD-2003-3581

Trust: 0.6

sources: CNVD: CNVD-2003-3581 // BID: 9194

REFERENCES

url:http://marc.theaimsgroup.com/?l=bugtraq&m=107108373729482&w=2

Trust: 0.6

url:http://www.netgear.com/

Trust: 0.3

url:/archive/1/347092

Trust: 0.3

sources: CNVD: CNVD-2003-3581 // BID: 9194

CREDITS

The disclosure of this issue has been credited to Jon Kamm @hotmail <jonkamm@hotmail.com>.

Trust: 0.3

sources: BID: 9194

SOURCES

db:CNVDid:CNVD-2003-3581
db:BIDid:9194

LAST UPDATE DATE

2022-05-17T01:57:27.177000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2003-3581date:2014-01-24T00:00:00
db:BIDid:9194date:2003-12-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2003-3581date:2003-12-10T00:00:00
db:BIDid:9194date:2003-12-10T00:00:00