ID

VAR-201106-0319


TITLE

NetGear WNDAP350 Wireless Access Point Information Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2011-2077

DESCRIPTION

The NetGear WNDAP350 is a wireless access device. The NetGear WNDAP350 wireless access point lacks the correct restrictions on access. An attacker can exploit the vulnerability to obtain sensitive information, including plain text management passwords or WPA ciphertext, through the download.php or BackupConfig.php script. WNDAP350 with firmware 2.0.1 and 2.0.9 are vulnerable; other firmware versions may also be affected

Trust: 0.81

sources: CNVD: CNVD-2011-2077 // BID: 48085

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2011-2077

AFFECTED PRODUCTS

vendor:netgearmodel:wndap350scope:eqversion:2.0.1

Trust: 0.9

vendor:netgearmodel:wndap350scope:eqversion:2.0.9

Trust: 0.9

sources: CNVD: CNVD-2011-2077 // BID: 48085

THREAT TYPE

network

Trust: 0.3

sources: BID: 48085

TYPE

Design Error

Trust: 0.3

sources: BID: 48085

EXTERNAL IDS

db:BIDid:48085

Trust: 0.9

db:CNVDid:CNVD-2011-2077

Trust: 0.6

sources: CNVD: CNVD-2011-2077 // BID: 48085

REFERENCES

url:http://www.securityfocus.com/bid/48085https

Trust: 0.6

url:http://www.netgear.com/

Trust: 0.3

url:https://revspace.nl/revelationspace/newsitem11x05x30x0

Trust: 0.3

sources: CNVD: CNVD-2011-2077 // BID: 48085

CREDITS

Juerd Waalboer

Trust: 0.3

sources: BID: 48085

SOURCES

db:CNVDid:CNVD-2011-2077
db:BIDid:48085

LAST UPDATE DATE

2022-05-17T02:00:11.492000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-2077date:2011-06-02T00:00:00
db:BIDid:48085date:2011-06-01T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2011-2077date:2011-06-02T00:00:00
db:BIDid:48085date:2011-06-01T00:00:00