Description
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
Problem types
CWE-287 Improper Authentication
Product status
Any version before v1.0.1.82
Any version before v1.0.1.82
Any version before v1.0.1.82
Any version before v1.0.1.82
Credits
chiphazard
References
www.netgear.com/support/product/ex5000
www.netgear.com/support/product/ex3110
www.netgear.com/support/product/ex6110
www.netgear.com/support/product/ex2800
kb.netgear.com/...442/January-2026-NETGEAR-Security-Advisory