Description
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
Published: 2019-10-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-7779 Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
History

No history.

Subscriptions

Netgear Ac1450 Ac1450 Firmware D8500 D8500 Firmware Dc112a Dc112a Firmware Jndr3000 Jndr3000 Firmware Lg2200d Lg2200d Firmware R4500 R4500 Firmware R6200 R6200 Firmware R6200v2 R6200v2 Firmware R6250 R6250 Firmware R6300 R6300 Firmware R6300v2 R6300v2 Firmware R6400 R6400 Firmware R6700 R6700 Firmware R6900 R6900 Firmware R6900p R6900p Firmware R7000 R7000 Firmware R7000p R7000p Firmware R7100lg R7100lg Firmware R7300 R7300 Firmware R7900 R7900 Firmware R8000 R8000 Firmware R8300 R8300 Firmware R8500 R8500 Firmware Wgr614v10 Wgr614v10 Firmware Wn2500rpv2 Wn2500rpv2 Firmware Wndr3400v2 Wndr3400v2 Firmware Wndr3700v3 Wndr3700v3 Firmware Wndr4000 Wndr4000 Firmware Wndr4500 Wndr4500 Firmware Wndr4500v2 Wndr4500v2 Firmware Wnr1000 Wnr1000 Firmware Wnr1000v3 Wnr1000v3 Firmware Wnr3500l Wnr3500l Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:40:15.201Z

Reserved: 2019-10-09T00:00:00.000Z

Link: CVE-2019-17372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-09T13:15:16.863

Modified: 2024-11-21T04:32:12.360

Link: CVE-2019-17372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses