NetGear WNDR Authentication Bypass / Information Disclosure

Summary
A number of NetGear WNDR devices contain an embedded SOAP service that is seemingly for use with the NetGear Genie application. This service allows for viewing and setting of certain router parameters. This SOAP service is prone to an authentication bypass.
Impact
Affected devices can be interrogated and hijacked
Solution
Ask the vendor for an update. Ensure remote WAN management is disabled on the affected devices. Only allow trusted devices access to the local network.
Affected
Platforms / Firmware confirmed affected: ---- NetGear WNDR3700v4 - V1.0.0.4SH NetGear WNDR3700v4 - V1.0.1.52 NetGear WNR2200 - V1.0.1.88 NetGear WNR2500 - V1.0.0.24 Additional platforms believed to be affected: ---- NetGear WNDR3800 NetGear WNDRMAC NetGear WPN824N NetGear WNDR4700
Detection
Send a special crafted POST request and check the response
References