CVE-2014-2969
8.3
Vector
AV:A/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 6.5 / Impact: 10.0
Source: NVD
Description
NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote attackers to upload firmware or read or modify memory contents, and consequently execute arbitrary code, via a request to (1) produce_burn.cgi, (2) register_debug.cgi, or (3) bootcode_update.cgi.
Affected (2)
Products: Netgear: Gs108pe Firmware, Gs108pe
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.0.5 | |
| All versions |
Related CWEs
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Timeline
No history available yet.