S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Sep 2, 2024

CVE-2024-6646 Scanner

CVE-2024-6646 scanner - Information Disclosure vulnerability in Netgear WN604

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6646
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /downloadFile.php of the component Web Interface. The manipulation of the argument file with the input config leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WN604by Netgear
20240710
wn604by netgear
AFFECTED< 20240710SAFE ✓≥ 20240710
Updated Sep 10, 2026View on NVD →
Detail

Netgear WN604 is a popular wireless access point used in small and medium-sized businesses for reliable internet connectivity. IT administrators use it to extend network coverage and improve wireless performance. The device is often employed in environments requiring robust wireless access with straightforward management capabilities. With the ability to serve multiple users and devices, the WN604 is integral in maintaining continuous and efficient network operations. Its ease of use and setup makes it a common choice for network expansion projects.

The Information Disclosure vulnerability in Netgear WN604 allows unauthorized access to sensitive information. This issue is located in the downloadFile.php interface, where improper validation permits attackers to retrieve files containing critical configuration details. Exploitation of this vulnerability can lead to unauthorized access to the router's administrative credentials. As a result, attackers could potentially control the router and compromise the security of the entire network.

The vulnerability lies in the downloadFile.php endpoint of the Netgear WN604, where a remote attacker can craft a specific request to access the "config" file. This file contains sensitive information such as administrator account and password details. The flaw is due to insufficient verification of the requested file's name or path, allowing attackers to download critical system configuration files. The endpoint responds with a 200 status code and serves the file with a content type of "application/force-download," confirming the presence of the vulnerability.

If exploited, this vulnerability could result in the disclosure of sensitive configuration files, including admin credentials. Attackers can leverage this access to gain unauthorized control over the router, manipulate network settings, or disrupt the network's operations. The compromised router could serve as a foothold for further attacks on connected devices, leading to a broader compromise of the network.

By using the S4E platform, you can quickly identify and mitigate vulnerabilities like the one affecting the Netgear WN604. Our platform offers comprehensive scanning capabilities, ensuring that your network devices are secure and up to date. Become a member today to benefit from continuous monitoring, timely alerts, and expert remediation advice that keeps your digital assets protected from emerging threats.

References:

Solution Advice
  • Update the Netgear WN604 firmware to the latest version available.
  • Restrict access to the downloadFile.php endpoint to trusted users only.
  • Implement strong authentication mechanisms for accessing configuration files.
  • Regularly review and monitor network logs for any unauthorized access attempts.
  • Consider replacing older devices that may not receive security updates.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-6646 scanner - Information Disclosure vulnerability in Netgear WN604 | S4E