Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://kb.netgear.com/30481/CVE-2016-1556-Notification?cid=wmt_netgear_organic | patch vendor advisory |
http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2016/Feb/112 | third party advisory mailing list |