CVE-2019-17372
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- netgear/ac1450 firmware · netgear/d8500 firmware · netgear/dc112a firmware · netgear/jndr3000 firmware · netgear/lg2200d firmware · netgear/r4500 firmware · netgear/r6200 firmware · netgear/r6200v2 firmware · netgear/r6250 firmware · netgear/r6300 firmware · netgear/r6300v2 firmware · netgear/r6400 firmware · netgear/r6700 firmware · netgear/r6900p firmware · netgear/r6900 firmware · netgear/r7000p firmware · netgear/r7000 firmware · netgear/r7100lg firmware · netgear/r7300 firmware · netgear/r7900 firmware · +13 more
- Source
- cve@mitre.org
References
- https://github.com/zer0yu/CVE_Request/blob/master/netgear/netgear_cgi_unauthorized_access_vulnerability.mdExploit, Third Party Advisory
- https://github.com/zer0yu/CVE_Request/blob/master/netgear/netgear_cgi_unauthorized_access_vulnerability.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.