CVE-2016-11015: CSRF
Published Oct 16, 2019
·Updated
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.XTWSZ-COMURLFilter.BlackList.1.URL parameter.
Affected Software
2 affected components
Netgear Jnr1010 Firmware<1.0.0.32
Netgear JNR1010
Event History
Oct 16, 2019
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
Description
Frequently Asked Questions
1
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2016-11015.
2
What is the severity of CVE-2016-11015?
The severity of CVE-2016-11015 is medium, with a severity value of 6.5.
3
What is the description of CVE-2016-11015?
CVE-2016-11015 is a vulnerability in NETGEAR JNR1010 devices before 1.0.0.32 that allows CGI-bin/webproc CSRF via the InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
4
What software is affected by CVE-2016-11015?
NETGEAR JNR1010 devices with firmware versions up to 1.0.0.32 are affected by CVE-2016-11015.
5
How can CVE-2016-11015 be fixed?
To fix CVE-2016-11015, users should update their NETGEAR JNR1010 devices to firmware version 1.0.0.32 or later.