Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Netgear DGN3500 #13

Closed
ghost opened this issue Jan 3, 2014 · 12 comments
Closed

Netgear DGN3500 #13

ghost opened this issue Jan 3, 2014 · 12 comments

Comments

@ghost
Copy link

ghost commented Jan 3, 2014

The port is open and respond on request. I tried the option that show admin password too and it work, so it's confirmed.

@elvanderb
Copy link
Owner

Thank you, added :)

@gsxarne
Copy link

gsxarne commented Jan 5, 2014

Hi,
i've tested my DGN3500 (Software V1.1.00.28_1.00.28GR) with telnet ( telnet routerip 32764“ ) and a portscan of the 32764 port and did not get a response.
I know another guy who has also a DGN3500 and also didnt get a response.

Greetings

@ghost
Copy link
Author

ghost commented Jan 5, 2014

Intresting, I have firmware V1.1.00.33_1.00.33
https://www.dropbox.com/s/l4n1ubq6hu6a2fh/screen.png

@gsxarne
Copy link

gsxarne commented Jan 5, 2014

Ok... lesson learned: Never trust a Windows telnet client:

this on is from a qnap nas:

http://abload.de/img/screenshot2014-01-051g8uyu.png

@elvanderb
Copy link
Owner

Why people don't use the provided PoC?! :)

@enryIT
Copy link
Contributor

enryIT commented Jan 16, 2014

Using this custom firmware http://alfie.altervista.org/amod/

probably not vulnerable (error: timed out)

@elvanderb
Copy link
Owner

Thank you :)
Could you do a pull request to add this solution to the list?

@looscillator
Copy link

Tested poc.py on DGN3500 (LAN Interface, did not test WAN)
affected international firmware versions:

V1.1.00.16_1.00.16
V1.1.00.22_1.00.22
V1.1.00.25_1.00.25
V1.1.00.28_1.00.28
V1.1.00.33_1.00.33

http://kb.netgear.com/app/answers/detail/a_id/2649

@nremond
Copy link

nremond commented Feb 3, 2014

Using http://alfie.altervista.org/amod/ fixed it for me. Great firmware.

@elvanderb
Copy link
Owner

I'll add it to the possible fixes, thanks ;)

@enryIT
Copy link
Contributor

enryIT commented Feb 3, 2014

already did that 12 days ago :D

@elvanderb
Copy link
Owner

This wasn't listed in the possible solutions :)
I'll add your comment in the credits ;)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants