ZeroHour

CVE-2019-17373

CVSS 3.1
9.8 critical
EPSS
2%p73
Published
()
Modified
Description

Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.

Vendors
netgear
Products
mbr1515 firmware, mbr1516 firmware, dgn2200 firmware, dgn2200m firmware, dgnd3700 firmware, wnr2000v2 firmware, wndr3300 firmware, wndr3400 firmware, wnr3500 firmware, wnr834bv2 firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.