Executive brief
A vulnerability in several NETGEAR router models allows unauthorized individuals to take full control of the device over the network. By accessing a hidden management URL, an attacker can change settings, steal the administrator password, or execute malicious code. This could lead to a complete compromise of the home or business network, allowing attackers to intercept traffic or use the device for further attacks.
Technical details
The vulnerability exists within the embedded web server (uhttpd) which exposes an unauthenticated CGI endpoint, 'apply_noauth.cgi', mirroring the functionality of the authenticated 'apply.cgi'. While some sensitive actions require a 'timestamp' variable acting as an anti-CSRF token, the token generation relies on a weak PRNG that can be brute-forced in fewer than 1,000 attempts. Furthermore, a stack buffer overflow was discovered in the handling of these requests. An unauthenticated attacker can combine the authentication bypass, token prediction, and buffer overflow to achieve remote code execution (RCE) with root privileges. This is exploitable via the LAN by default, or via the WAN if remote management is enabled.
Affected products
- NETGEAR WNR2000v5 All firmware versions prior to 1.0.0.42
- NETGEAR WNR2000v4 All firmware versions prior to 1.0.0.62
- NETGEAR WNR2000v3 All firmware versions prior to 1.0.2.62
- NETGEAR WNR2020 All firmware versions prior to 1.1.0.48
- NETGEAR WNR1000v4 All firmware versions prior to 1.1.0.46
Timeline
- 2016-12-20: disclosed: Initial 0-day disclosure by researcher Pedro Ribeiro
- 2016-12-22: advisory: NETGEAR published initial security advisory PSV-2016-0255
- 2017-01-26: patched: Production firmware updates released for WNR2000 series
- 2017-01-30: advisory: CVE-2016-10176 published in NVD
References
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability
- http://seclists.org/fulldisclosure/2016/Dec/72
- http://www.securityfocus.com/bid/95867
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt
- https://www.exploit-db.com/exploits/40949/