S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-5649 Scanner

Detects 'Admin Credential Disclosure' vulnerability in Netgear DGN2200 and DGND3700 affects v. DGN2200-1.0.0.50_7.0.50 and DGND3700-1.0.0.17_1.0.17.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-5649
9.8
CVSS

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
DGN2200by Netgear
DGN2200-V1.0.0.50_7.0.50
DGND3700by Netgear
DGND3700-V1.0.0.17_1.0.17
Updated Aug 22, 2026View on NVD →
Detail

The Netgear DGN2200 and DGND3700 are popular home routers used for connecting multiple devices to the internet. These products are designed to provide a fast and reliable internet connection to households and small businesses. They are easy to install, configure, and use, making them a go-to choice for many users.

However, recent security research has discovered a serious vulnerability in these routers, designated CVE-2016-5649. This vulnerability allows a remote attacker to gain access to the 'BSW_cxttongr.htm' page without any authentication, which exposes the admin password in clear text before redirecting to the absw_vfysucc.cgia page. An attacker can easily use the compromised password to gain full access to the targeted router and its web interface.

The implications of this vulnerability are significant. An attacker who gains unauthorized access to the router can easily steal sensitive data, such as login credentials, personal information, and financial data. Additionally, they can use the router to launch attacks on other devices on the network or use it as a stepping stone to other systems on the internet.

In conclusion, it is essential to stay informed about the security of our digital assets, including our home routers. Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. By taking the necessary precautions, we can keep our networks and devices secure and protect ourselves from malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update the router to the latest firmware version. Netgear has released a patch that addresses this vulnerability.
  • Ensure that remote management is disabled on the router.
  • Change the default administrator password to a strong, unique password.
  • Use strong WPA2 encryption to secure the wireless network.
  • Regularly review the router logs for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-5649 scanner - Admin Credential Disclosure vulnerability in Netgear DGN2200 and DGND3700 | S4E