CVE-2015-8289: Infoleak
The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp HTML source code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8289?
CVE-2015-8289 is classified as a high severity vulnerability due to the risk of exposing administrator passwords to remote attackers.
How do I fix CVE-2015-8289?
To fix CVE-2015-8289, you should upgrade to the latest firmware version of the NETGEAR D3600 and D6000 devices.
What devices are affected by CVE-2015-8289?
CVE-2015-8289 affects NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier.
What type of attack is possible with CVE-2015-8289?
CVE-2015-8289 allows remote attackers to uncover the cleartext administrator password through the password-recovery feature.
Is CVE-2015-8289 still a threat if my device firmware has been updated?
If your device firmware has been updated to a version later than 1.0.0.49, then CVE-2015-8289 should no longer pose a threat.