漏洞标题
N/A
漏洞描述信息
NETGEAR C7800路由器在运行固件版本6.01.07(以及其他版本可能也存在)时,其管理web界面通过基础认证来验证用户身份,该认证方式使用HTTP头,其中包含了明文用户名和密码的base64值。由于该web服务器默认情况下不使用传输安全措施,因此在客户端通过WLAN或LAN向路由器发起的每一次认证请求中,如果攻击者能够执行中间人攻击,管理凭证将容易受到监听。
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
不充分的凭证保护机制
漏洞标题
N/A
漏洞描述信息
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.
CVSS信息
N/A
漏洞类别
N/A