Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.

Project Subscriptions

Vendors Products
Netgear Subscribe
Ac1450 Firmware Subscribe
D8500 Firmware Subscribe
Dc112a Firmware Subscribe
Jndr3000 Subscribe
Jndr3000 Firmware Subscribe
Lg2200d Subscribe
Lg2200d Firmware Subscribe
R4500 Firmware Subscribe
R6200 Firmware Subscribe
R6200v2 Subscribe
R6200v2 Firmware Subscribe
R6250 Firmware Subscribe
R6300 Firmware Subscribe
R6300v2 Subscribe
R6300v2 Firmware Subscribe
R6400 Firmware Subscribe
R6700 Firmware Subscribe
R6900 Firmware Subscribe
R6900p Firmware Subscribe
R7000 Firmware Subscribe
R7000p Firmware Subscribe
R7100lg Subscribe
R7100lg Firmware Subscribe
R7300 Firmware Subscribe
R7900 Firmware Subscribe
R8000 Firmware Subscribe
R8300 Firmware Subscribe
R8500 Firmware Subscribe
Wgr614v10 Subscribe
Wgr614v10 Firmware Subscribe
Wn2500rpv2 Subscribe
Wn2500rpv2 Firmware Subscribe
Wndr3400v2 Subscribe
Wndr3400v2 Firmware Subscribe
Wndr3700v3 Subscribe
Wndr3700v3 Firmware Subscribe
Wndr4000 Subscribe
Wndr4000 Firmware Subscribe
Wndr4500 Subscribe
Wndr4500 Firmware Subscribe
Wndr4500v2 Subscribe
Wndr4500v2 Firmware Subscribe
Wnr1000 Subscribe
Wnr1000 Firmware Subscribe
Wnr1000v3 Subscribe
Wnr1000v3 Firmware Subscribe
Wnr3500l Subscribe
Wnr3500l Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-7779 Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:40:15.201Z

Reserved: 2019-10-09T00:00:00

Link: CVE-2019-17372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-09T13:15:16.863

Modified: 2024-11-21T04:32:12.360

Link: CVE-2019-17372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses