Skip to main content
Medium May 26, 2012

Netgear Information Disclosure

Several NETGEAR devices expose /currentsetting.htm without authentication, leaking the device model, firmware version, and other metadata that lets an attacker fingerprint the router before launching model-specific exploits.

CVSS Score

5.3 / 10.0

Severity

Medium

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Advisory

VendorNETGEAR
ModelsDGND3300v2, WNR2000v2, DGN1000, N300
FirmwareV2.1.00.48_1.00.48, V1.1.0.41WW, V1.0.0.34_29.0.45NA
ImpactReveals model, firmware, and other device metadata
Attack VectorRemote, no authentication required

Description

Several NETGEAR devices expose /currentsetting.htm without authentication. The page returns the device model, firmware version, and other information that helps an attacker fingerprint the device before targeting it with model-specific exploits.

Remediation

No vendor fix. Restrict remote management to trusted networks.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Medium April 27, 2026

Ladybird JSON Parser UTF-8 Validation Denial of Service

Invalid UTF-8 input could crash Ladybird's JSON parser with SIGILL, causing a denial of service in applications processing untrusted JSON. Discovered by Websec co-founder Paulino Calderon.

Severity:
CVSS: 5.5
View advisory
Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory