First published: Mon Jun 20 2016(Updated: )
NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR D3600 firmware | =1.0.0.49 | |
NETGEAR D3600 firmware | ||
NETGEAR D6000 firmware | <=1.0.0.49 | |
NETGEAR D6000 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8288 is considered a high-severity vulnerability due to the use of a hardcoded private key that can be exploited remotely.
To mitigate CVE-2015-8288, users should upgrade to the latest firmware version that does not use hardcoded keys.
CVE-2015-8288 affects NETGEAR D3600 devices with firmware version 1.0.0.49 and NETGEAR D6000 devices with firmware version 1.0.0.49 and earlier.
The implications of CVE-2015-8288 include potential unauthorized access and compromise of sensitive data due to the crackable cryptographic protection.
CVE-2015-8288 primarily allows remote attackers to exploit the vulnerability, requiring no local access to the affected devices.