CVE-2017-12575: High severity Aterm WG2600HP2 firmware vulnerability
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sending a crafted HTTP request to retrieve DHCP clients, firmware version, and network status (ex.: curl -X http://[IP]/atermhttpif.cgi/negotiate -d "REQID=SUPPORTIFGET").
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12575?
CVE-2017-12575 has a medium severity rating due to the risk of unauthorized access to sensitive configuration data.
How do I fix CVE-2017-12575?
To fix CVE-2017-12575, upgrade the NEC Aterm WG2600HP2 firmware to the latest version that requires authentication for all web service APIs.
What types of devices are affected by CVE-2017-12575?
CVE-2017-12575 affects the NEC Aterm WG2600HP2 router running firmware version 1.0.2.
Can CVE-2017-12575 be exploited remotely?
Yes, an attacker can exploit CVE-2017-12575 remotely by sending a crafted HTTP request to the router.
What information could be exposed due to CVE-2017-12575?
CVE-2017-12575 could allow an attacker to retrieve DHCP client information and firmware version details without authentication.