Vulnerabilities > CVE-2004-2557 - Unspecified vulnerability in Netgear Wg602 1.7.14

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
netgear
nessus

Summary

NetGear WG602 (aka WG602v1) Wireless Access Point 1.7.14 has a hardcoded account of username "superman" and password "21241036", which allows remote attackers to modify the configuration.

Vulnerable Configurations

Part Description Count
Hardware
Netgear
1

Nessus

NASL familyCGI abuses
NASL idNETGEAR_HIDDEN_PASSWORD.NASL
descriptionNETGEAR ships at least one device with a built-in administrator account. This account cannot be changed via the configuration interface and enables a remote attacker to control the NETGEAR device. To duplicate this error, simply point your browser to a vulnerable machine, and log in (when prompted) with : userid = super password = 5777364 or : userid = superman password = 21241036
last seen2020-06-01
modified2020-06-02
plugin id12258
published2004-06-03
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/12258
titleNETGEAR Wireless Access Point Hardcoded Default Password