Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netgear
Subscribe
|
Dgn2200
Subscribe
Dgn2200 Firmware
Subscribe
Dgn2200m
Subscribe
Dgn2200m Firmware
Subscribe
Dgnd3700
Subscribe
Dgnd3700 Firmware
Subscribe
Mbr1515
Subscribe
Mbr1515 Firmware
Subscribe
Mbr1516
Subscribe
Mbr1516 Firmware
Subscribe
Wndr3300
Subscribe
Wndr3300 Firmware
Subscribe
Wndr3400
Subscribe
Wndr3400 Firmware
Subscribe
Wnr2000v2
Subscribe
Wnr2000v2 Firmware
Subscribe
Wnr3500
Subscribe
Wnr3500 Firmware
Subscribe
Wnr834bv2
Subscribe
Wnr834bv2 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-7780 | Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.309Z
Reserved: 2019-10-09T00:00:00
Link: CVE-2019-17373
No data.
Status : Modified
Published: 2019-10-09T13:15:20.193
Modified: 2024-11-21T04:32:12.537
Link: CVE-2019-17373
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD