Sense of Security - Security Advisory - SOS-12-005 Release Date. 13-May-2012 Last Update. - Vendor Notification Date. 06-Mar-2012 Product. NETGEAR WNDRMAC Platform. Hardware Affected versions. 1.0.0.22 and below Severity Rating. High Impact. Exposure of sensitive information Attack Vector. From remote without authentication Solution Status. Currently no software update; the vulnerable functionality can be disabled CVE reference. CVE - not yet assigned Details. The NETGEAR Wireless Extreme for Mac computer and PCs (WNDRMAC) is a N600 wireless dual-band gigabit router. The router discloses sensitive information in the page source, if a previous password recovery has been successfully completed, which allows an attacker to login to the device. Proof of Concept. Viewing the source code of the page you are presented with when you fail to login successfully with the administrator account exposes the routers serial number which is required to get to the recovery questions section. http://x.x.x.x/unauth.cgi 401 Authorization