PoC Index

CVE-2009-2257

HIGH 7.8EPSS 7.2%

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/.

CVSS v2.0
7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS
7.18% chance of exploitation in the next 30 days, 94th percentile
Published
2009-06-30
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related