An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-04T19:47:55.638Z
Reserved: 2019-01-04T00:00:00
Link: CVE-2019-5054
No data.
Status : Modified
Published: 2019-09-11T22:15:19.353
Modified: 2024-11-21T04:44:15.590
Link: CVE-2019-5054
No data.
OpenCVE Enrichment
No data.
Weaknesses