CVE-2019-5054
An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.13% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- netgear/wnr2000 firmware
- Source
- talos-cna@cisco.com
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0831Exploit, Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0831Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.