First published: Wed Oct 16 2019(Updated: )
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Jnr1010 Firmware | <1.0.0.32 | |
NETGEAR JNR1010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-11014 is a vulnerability found in NETGEAR JNR1010 devices before version 1.0.0.32, which allows incorrect access control due to a special case with the authentication cookie.
CVE-2016-11014 has a severity rating of 9.8, which is considered critical.
NETGEAR JNR1010 devices before version 1.0.0.32 are affected by CVE-2016-11014.
To fix CVE-2016-11014, users should update their NETGEAR JNR1010 devices to version 1.0.0.32 or higher.
More information about CVE-2016-11014 can be found at the following references: [Link 1](https://cybersecurityworks.com/zerodays/cve-2016-11014-netgear.html), [Link 2](https://github.com/cybersecurityworks/Disclosed/issues/14), [Link 3](https://khalil-shreateh.com/khalil.shtml/it-highlights/593-Netgear-1.0.0.24-Bypass---Improper-Session-Management--.html).