CVE-2016-5638: Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877 reveals some sensitive information such as 2.4GHz & 5GHz Wireless Network Name (SSID) and Network Key (Password) in clear text
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.401.0.6877. Genie app adds some capabilities over the Web GUI and can be accessed even when you are away from home. A remote attacker can access genieping.htm or genieping2.htm or genieping3.htm page without authentication. Once accessed, the page will be redirected to the aCongratulations2.htma page, which reveals some sensitive information such as 2.4GHz & 5GHz Wireless Network Name (SSID) and Network Key (Password) in clear text.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5638?
CVE-2016-5638 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2016-5638?
To mitigate CVE-2016-5638, update the firmware of your NETGEAR WNDR4500 to the latest version available.
What type of vulnerability is CVE-2016-5638?
CVE-2016-5638 is an information disclosure vulnerability affecting the NETGEAR WNDR4500's genie app.
Can CVE-2016-5638 be exploited remotely?
Yes, CVE-2016-5638 can be exploited remotely by unauthorized attackers.
Which devices are affected by CVE-2016-5638?
CVE-2016-5638 specifically affects the NETGEAR WNDR4500 router running firmware version 1.0.1.40_1.0.6877.