CVE-2019-17372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
09/10/2019
Last modified:
18/10/2019

Description

Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:ac1450_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ac1450:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:d8500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:d8500:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:dc112a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:dc112a:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jndr3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:jndr3000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:lg2200d_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:lg2200d:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r4500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r4500:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6200:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6200v2_firmware:-:*:*:*:*:*:*:*