Vulnerabilities > CVE-2016-1524 - Unspecified vulnerability in Netgear Prosafe Network Management Software 300 1.5.0.11

047910
CVSS 8.3 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
low complexity
netgear
exploit available
metasploit

Summary

Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI. <a href="http://cwe.mitre.org/data/definitions/434.html">CWE-434: Unrestricted Upload of File with Dangerous Type</a>

Vulnerable Configurations

Part Description Count
Application
Netgear
1

Exploit-Db

descriptionNETGEAR ProSafe Network Management System NMS300 - Multiple Vulnerabilities. CVE-2016-1524,CVE-2016-1525. Webapps exploit for hardware platform
fileexploits/hardware/webapps/39412.txt
idEDB-ID:39412
last seen2016-02-05
modified2016-02-04
platformhardware
port
published2016-02-04
reporterPedro Ribeiro
sourcehttps://www.exploit-db.com/download/39412/
titleNETGEAR ProSafe Network Management System NMS300 - Multiple Vulnerabilities
typewebapps

Metasploit

descriptionNetgear's ProSafe NMS300 is a network management utility that runs on Windows systems. The application has a file download vulnerability that can be exploited by an authenticated remote attacker to download any file in the system. This module has been tested with versions 1.5.0.2, 1.4.0.17 and 1.1.0.13.
idMSF:AUXILIARY/ADMIN/HTTP/NETGEAR_AUTH_DOWNLOAD
last seen2020-05-31
modified2018-09-15
published2016-02-03
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/admin/http/netgear_auth_download.rb
titleNETGEAR ProSafe Network Management System 300 Authenticated File Download

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/135618/netgear_nms_rce.txt
idPACKETSTORM:135618
last seen2016-12-05
published2016-02-07
reporterPedro Ribeiro
sourcehttps://packetstormsecurity.com/files/135618/Netgear-Pro-NMS-300-Code-Execution-File-Download.html
titleNetgear Pro NMS 300 Code Execution / File Download

The Hacker News

idTHN:E0863B17DEEAD331430C9E081425147F
last seen2018-01-27
modified2016-02-05
published2016-02-05
reporterRakesh Krishnan
sourcehttps://thehackernews.com/2016/02/network-management-system.html
titleCritical Flaws Found in NETGEAR Network Management System