Summary
A number of NetGear WNDR devices contain an embedded SOAP service that is seemingly for use with the NetGear Genie application. This service allows for viewing and setting of certain router parameters. This SOAP service is prone to an authentication bypass.
Impact
Affected devices can be interrogated and hijacked
Solution
Ask the vendor for an update. Ensure remote WAN management is disabled on the affected devices.
Only allow trusted devices access to the local network.
Affected
Platforms / Firmware confirmed affected:
----
NetGear WNDR3700v4 - V1.0.0.4SH
NetGear WNDR3700v4 - V1.0.1.52
NetGear WNR2200 - V1.0.1.88
NetGear WNR2500 - V1.0.0.24
Additional platforms believed to be affected:
----
NetGear WNDR3800
NetGear WNDRMAC
NetGear WPN824N
NetGear WNDR4700
Detection
Send a special crafted POST request and check the response
References
Updated on 2015-03-25