CVE-2019-17373
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/10/2019
Last modified:
24/08/2020
Description
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netgear:mbr1515_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:mbr1515:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:mbr1516_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:mbr1516:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:dgn2200_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:dgn2200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:dgn2200m_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:dgn2200m:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:dgnd3700_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:dgnd3700:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wnr2000v2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:wnr2000v2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wndr3300_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netgear:wndr3300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wndr3400_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



