CVE-2017-5521
published 2017-01-17CVE-2017-5521: An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They…
PriorityP190high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
89.29%
99.8th percentile
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | ac1450_firmware | — | — |
| netgear | d6220_firmware | — | — |
| netgear | d6300_firmware | — | — |
| netgear | d6300b_firmware | — | — |
| netgear | d6400_firmware | — | — |
| netgear | dgn2200bv4_firmware | — | — |
| netgear | r6200_firmware | — | — |
| netgear | r6300_firmware | — | — |
| netgear | vegn2610_firmware | — | — |
| netgear | wndr3700v3_firmware | — | — |
| netgear | wndr4000_firmware | — | — |
| netgear | wndr4500_firmware | — | — |
| netgear | wnr1000v3_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated HTTP GET requests to /unauth.cgi followed by requests to /passwordrecovered.cgi on NETGEAR router management interfaces — this two-step sequence is the exploit chain for CVE-2017-5521. ↗
- →Alert on HTTP requests to /passwordrecovered.cgi containing an 'id=' parameter, especially from unauthenticated sessions or after a cancelled authentication attempt. ↗
- →Monitor for exploitation attempts against NETGEAR router web management panels (R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, R8000) — the exploit is accessible over LAN, WLAN, or WAN if remote management is enabled. ↗
- →A Metasploit auxiliary module (auxiliary/gather/netgear_password_disclosure) exists for this CVE; detect its use via IDS/IPS signatures matching the two-CGI request pattern. ↗
- ·The exploit fails if password recovery is enabled on the router — the router will instead prompt for previously configured security questions, making the attack ineffective. ↗
- ·Even after disabling password recovery, the exploit may still fail because the router retains the security question prompt persistently. ↗
- ·Remote exploitation requires the remote management option to be enabled on the router; LAN/WLAN access is sufficient without it. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck8.1HIGH
cisa8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6cqf-r56h-g5xf: An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices
ghsa_unreviewed·2022-05-17
CVE-2017-5521 [HIGH] CWE-200 GHSA-6cqf-r56h-g5xf: An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery
VulnCheck
NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
vulncheck·2017·CVSS 8.1
CVE-2017-5521 [HIGH] CWE-200 NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.
Affected: NETGEAR Multiple Devices
Required Action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.
Exploitation References: https://www.trendmicro.com/en_us/research/18/g/vpnfilter-affected-devices-still-riddled-with-19-vulnerabilities.html; https://www.researchgate.net/publication/348602660_An_analysis_of_the_use_of_CVEs_by_IoT_malware; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-05-0
CISA
NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
cisa·2022-09-08·CVSS 8.1
CVE-2017-5521 [HIGH] CWE-200 NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
Vulnerability: NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
Affected: NETGEAR Multiple Devices
Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.
Required Action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.
Notes: https://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability; https://nvd.nist.gov/vuln/detail/CVE-2017-5521
Remediation Due Date: 2022-09-29
Suricata
ET EXPLOIT Netgear passwordrecovered.cgi attempt
suricata·2014-01-15
CVE-2017-5521 ET EXPLOIT Netgear passwordrecovered.cgi attempt
ET EXPLOIT Netgear passwordrecovered.cgi attempt
Rule: alert http any any -> any any (msg:"ET EXPLOIT Netgear passwordrecovered.cgi attempt"; flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:"/passwordrecovered.cgi?id="; nocase; reference:url,www.securityfocus.com/archive/1/530743/30/0/threaded; reference:url,www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-003/?fid=8911; reference:cve,2017-5521; classtype:attempted-admin; sid:2017969; rev:6; metadata:created_at 2014_01_15, cve CVE_2017_5521, signature_severity Major, updated_at 2024_03_06;)
Exploit-DB
Netgear Routers - Password Disclosure
exploitdb·2017-01-30·CVSS 8.1
CVE-2017-5521 [HIGH] Netgear Routers - Password Disclosure
Netgear Routers - Password Disclosure
---
Trustwave SpiderLabs Security Advisory TWSL2017-003:
Multiple Vulnerabilities in NETGEAR Routers
Published: 01/30/2017
Version: 1.0
Vendor: NETGEAR (http://www.netgear.com/)
Product: Multiple products
Finding 1: Remote and Local Password Disclosure
Credit: Simon Kenin of Trustwave SpiderLabs
CVE: CVE-2017-5521
Version affected:
# AC1450 V1.0.0.34_10.0.16 (Latest)
# AC1450 V1.0.0.22_1.0.10
# AC1450 V1.0.0.14_1.0.6
# D6400 V1.0.0.44_1.0.44 (V1.0.0.52_1.0.52 and above not affected)
# D6400 V1.0.0.34_1.3.34
# D6400 V1.0.0.38_1.1.38
# D6400 V1.0.0.22_1.0.22
# DC112A V1.0.0.30_1.0.60 (Latest)
# DGN2200v4 V1.0.0.24_5.0.8 (V1.0.0.66_1.0.66 is latest and is not affected)
# JNDR3000 V1.0.0.18_1.0.16 (Latest)
# R6200 V1.0.1.48_1.0.37 (V1.0.1.52_1.0.41
Metasploit
NETGEAR Administrator Password Disclosure
metasploit
NETGEAR Administrator Password Disclosure
NETGEAR Administrator Password Disclosure
This module will collect the password for the `admin` user. The exploit will not complete if password recovery is set on the router. The password is received by passing the token generated from `unauth.cgi` to `passwordrecovered.cgi`. This exploit works on many different NETGEAR products. The full list of affected products is available in the 'References' section.
Nuclei
NETGEAR Routers - Authentication Bypass
nuclei·CVSS 8.1
CVE-2017-5521 [HIGH] NETGEAR Routers - Authentication Bypass
NETGEAR Routers - Authentication Bypass
NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server.
Template:
id: CVE-2017-5521
info:
name: NETGEAR Routers - Authentication Bypass
author: princechaddha
severity: high
description: |
NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server.
impact: |
Successful exploitation of this vulnerability can lead to unauthorized configuration changes, network compromise, and potential exposure of sensitive information.
remed
Trendmicro
IoT Attack as Discussed in the Cybercrime Underground
blogs_trendmicro·2019-09-10
IoT Attack as Discussed in the Cybercrime Underground
Cyber Crime
## IoT Attack as Discussed in the Cybercrime Underground
We looked into IoT-related forums from several cybercrime underground communities and found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks.
By: Stephen Hilt, Vladimir Kropotov, Fernando Merces, Mayra Rosario Fuentes, David Sancho 2019/09/10 Read time: ( words)
Save to Folio
Updated at 12:00 PM EDT, September 12, 2019, to more accurately describe certain forums.
In our paper “ The Internet of Things in the Cybercrime Underground ,” we looked into IoT-related discussions from several cybercrime underground communities. We found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks. Unsurprisingly, exposed devices and vulnerabilities were of
Trendmicro
IoT Attack as Discussed in the Cybercrime Underground
blogs_trendmicro·2019-09-10
IoT Attack as Discussed in the Cybercrime Underground
Cyber Crime
# IoT Attack as Discussed in the Cybercrime Underground
We looked into IoT-related forums from several cybercrime underground communities and found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks.
By: Stephen Hilt, Vladimir Kropotov, Fernando Merces, Mayra Rosario Fuentes, David Sancho
2019/09/10
Read time: ( words)
Save to Folio
Updated at 12:00 PM EDT, September 12, 2019, to more accurately describe certain forums.
In our paper “The Internet of Things in the Cybercrime Underground,” we looked into IoT-related discussions from several cybercrime underground communities. We found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks. Unsurprisingly, exposed devices and vulnerabilities were of g
Trendmicro
IoT Attack as Discussed in the Cybercrime Underground
blogs_trendmicro·2019-09-10
IoT Attack as Discussed in the Cybercrime Underground
Ciberdelincuencia
## IoT Attack as Discussed in the Cybercrime Underground
We looked into IoT-related forums from several cybercrime underground communities and found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks.
By: Stephen Hilt, Vladimir Kropotov, Fernando Merces, Mayra Rosario Fuentes, David Sancho Sep 10, 2019 Read time: ( words)
Save to Folio
Updated at 12:00 PM EDT, September 12, 2019, to more accurately describe certain forums.
In our paper “ The Internet of Things in the Cybercrime Underground ,” we looked into IoT-related discussions from several cybercrime underground communities. We found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks. Unsurprisingly, exposed devices and vulnerabilities
Trendmicro
IoT Attack as Discussed in the Cybercrime Underground
blogs_trendmicro·2019-09-10
IoT Attack as Discussed in the Cybercrime Underground
Cyber Crime
# IoT Attack as Discussed in the Cybercrime Underground
We looked into IoT-related forums from several cybercrime underground communities and found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks.
By: Stephen Hilt, Vladimir Kropotov, Fernando Merces, Mayra Rosario Fuentes, David Sancho
Sep 10, 2019
Read time: ( words)
Save to Folio
Updated at 12:00 PM EDT, September 12, 2019, to more accurately describe certain forums.
In our paper “The Internet of Things in the Cybercrime Underground,” we looked into IoT-related discussions from several cybercrime underground communities. We found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks. Unsurprisingly, exposed devices and vulnerabilities were of
Trendmicro
IoT Attack as Discussed in the Cybercrime Underground
blogs_trendmicro·2019-09-10
IoT Attack as Discussed in the Cybercrime Underground
Cyber Crime
## IoT Attack as Discussed in the Cybercrime Underground
We looked into IoT-related forums from several cybercrime underground communities and found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks.
By: Stephen Hilt, Vladimir Kropotov, Fernando Merces, Mayra Rosario Fuentes, David Sancho Sep 10, 2019 Read time: ( words)
Save to Folio
Updated at 12:00 PM EDT, September 12, 2019, to more accurately describe certain forums.
In our paper “ The Internet of Things in the Cybercrime Underground ,” we looked into IoT-related discussions from several cybercrime underground communities. We found discussions ranging from tutorials to actual monetization schemes for IoT-related attacks. Unsurprisingly, exposed devices and vulnerabilities were
Trendmicro
VPNFilter-affected Devices Still Riddled with 19 Bugs
blogs_trendmicro·2018-07-13
VPNFilter-affected Devices Still Riddled with 19 Bugs
IoT
## VPNFilter-affected Devices Still Riddled with 19 Bugs
This blog tackles the VPNFilter malware and if deployed devices are vulnerable to it. Based on our data, plenty of the devices are still using old firmware versions. In fact, 19 known vulnerabilities can still be detected in devices up to this day.
By: Tony Yang, Peter Lee Jul 13, 2018 Read time: ( words)
Save to Folio
Our IoT scanning tool allows users to identify if connected devices (e.g. routers, network attached storage devices, IP cameras, and printers) in a given network are vulnerable to security risks and vulnerabilities, such as those related to Mirai, Reaper, and WannaCry.
We gather our data from the Trend Micro™ Home Network Security solution and HouseCall™ for Home Networks scanner. HouseCall for Home Networks
Trendmicro
VPNFilter-affected Devices Still Riddled with 19 Bugs
blogs_trendmicro·2018-07-13
VPNFilter-affected Devices Still Riddled with 19 Bugs
IoT
# VPNFilter-affected Devices Still Riddled with 19 Bugs
This blog tackles the VPNFilter malware and if deployed devices are vulnerable to it. Based on our data, plenty of the devices are still using old firmware versions. In fact, 19 known vulnerabilities can still be detected in devices up to this day.
By: Tony Yang, Peter Lee
2018/07/13
Read time: ( words)
Save to Folio
Our IoT scanning tool allows users to identify if connected devices (e.g. routers, network attached storage devices, IP cameras, and printers) in a given network are vulnerable to security risks and vulnerabilities, such as those related to Mirai, Reaper, and WannaCry.
We gather our data from the Trend Micro™ Home Network Security solution and HouseCall™ for Home Networks scanner. HouseCall for Home Networks is
Trendmicro
VPNFilter-affected Devices Still Riddled with 19 Bugs
blogs_trendmicro·2018-07-13
VPNFilter-affected Devices Still Riddled with 19 Bugs
IoT
## VPNFilter-affected Devices Still Riddled with 19 Bugs
This blog tackles the VPNFilter malware and if deployed devices are vulnerable to it. Based on our data, plenty of the devices are still using old firmware versions. In fact, 19 known vulnerabilities can still be detected in devices up to this day.
By: Tony Yang, Peter Lee 2018/07/13 Read time: ( words)
Save to Folio
Our IoT scanning tool allows users to identify if connected devices (e.g. routers, network attached storage devices, IP cameras, and printers) in a given network are vulnerable to security risks and vulnerabilities, such as those related to Mirai, Reaper, and WannaCry.
We gather our data from the Trend Micro™ Home Network Security solution and HouseCall™ for Home Networks scanner. HouseCall for Home Networks is
Fortinet
FortiGuard Labs Telemetry: Round up of 2015 and 2016 IoT Threats (Part 2 Home Routers)
blogs_fortinet·2017-03-13
FortiGuard Labs Telemetry: Round up of 2015 and 2016 IoT Threats (Part 2 Home Routers)
FORTIGUARD LABS THREAT RESEARCH
FortiGuard Labs Telemetry: Round up of 2015 and 2016 IoT Threats (Part 2 Home Routers)
By Gavin Chow | March 13, 2017
In our last post Round up of 2016 IoT Threats we compared 2015 and 2016 global threat telemetry for IoT devices collected by our FortiGuard Labs.
In this post, we will examine why home routers had a such a huge increase in IPS signature hits in 2016, when compared to 2015.
Home Routers
In 2015, home routers had the most IPS signature hits at around 821,000. But this number exploded exponentially in 2016, to more than 25 billion hits. We can see the exponential increase more clearly when we compare both years using a size comparison chart as shown below (note that 2015 is just a tiny dot compared to 2016’s much bigger circle).
What contr
arXiv
Mens Sana In Corpore Sano: Sound Firmware Corpora for Vulnerability Research
arxiv_fulltext·2024-11-21
Mens Sana In Corpore Sano: Sound Firmware Corpora for Vulnerability Research
Mens Sana In Corpore Sano:\ Firmware Corpora for Vulnerability Research
René Helmke1,
Elmar Padilla1, and
Nils Aschenbruck^
1Fraunhofer FKIE, Cyber Analysis & Defense, Germany, \firstname.lastname\@fkie.fraunhofer.de
^ Osnabrück University, Distributed Systems Group, Germany, [email protected]
## Abstract
Firmware corpora for vulnerability research should be scientifically sound.
Yet, several practical challenges complicate the creation of sound corpora:
Sample acquisition, e.g., is hard and one must overcome the barrier of proprietary or encrypted data.
As image contents are unknown prior analysis,
it is hard to select high-quality samples that can satisfy scientific demands.
Ideally, we help each other out by sharing data.
But here, sharing is problematic due to copyright laws.
Inste
http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerabilityhttp://www.securityfocus.com/bid/95457https://www.exploit-db.com/exploits/41205/http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerabilityhttp://www.securityfocus.com/bid/95457https://www.exploit-db.com/exploits/41205/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5521
2017-01-17
Published
2022-09-08
Added to CISA KEV
Exploited in the wild