Vulnerability Description
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Mbr1515 Firmware | - |
| Netgear | Mbr1515 | - |
| Netgear | Mbr1516 Firmware | - |
| Netgear | Mbr1516 | - |
| Netgear | Dgn2200 Firmware | - |
| Netgear | Dgn2200 | - |
| Netgear | Dgn2200M Firmware | - |
| Netgear | Dgn2200M | - |
| Netgear | Dgnd3700 Firmware | - |
| Netgear | Dgnd3700 | - |
| Netgear | Wnr2000V2 Firmware | - |
| Netgear | Wnr2000V2 | - |
| Netgear | Wndr3300 Firmware | - |
| Netgear | Wndr3300 | - |
| Netgear | Wndr3400 Firmware | - |
| Netgear | Wndr3400 | - |
| Netgear | Wnr3500 Firmware | - |
| Netgear | Wnr3500 | - |
| Netgear | Wnr834Bv2 Firmware | - |
| Netgear | Wnr834Bv2 | - |
References
- https://github.com/zer0yu/CVE_Request/blob/master/netgear/Netgear_web_interface_Third Party Advisory
- https://github.com/zer0yu/CVE_Request/blob/master/netgear/Netgear_web_interface_Third Party Advisory
FAQ
What is CVE-2019-17373?
CVE-2019-17373 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, D...
How severe is CVE-2019-17373?
CVE-2019-17373 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17373?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Mbr1515 Firmware, Netgear Mbr1515, Netgear Mbr1516 Firmware, Netgear Mbr1516, Netgear Dgn2200 Firmware.