Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sending a crafted HTTP request to retrieve DHCP clients, firmware version, and network status (ex.: curl -X http://[IP]/aterm_httpif.cgi/negotiate -d "REQ_ID=SUPPORT_IF_GET").
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NEC Aterm WG2600HP2 安全漏洞
Vulnerability Description
NEC Aterm WG2600HP2是日本电气(NEC)公司的一款无线路由器。 NEC Aterm WG2600HP2 1.0.2版本中存在安全漏洞,该漏洞源于一些用于访问和设置配置的Web服务APIs没有要求用户进行身份验证。攻击者可通过发送特制的HTTP请求利用该漏洞检索DHCP客户端、固件版本和网络状态。
CVSS Information
N/A
Vulnerability Type
N/A