First published: Wed Oct 16 2019(Updated: )
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Jnr1010 Firmware | <1.0.0.32 | |
NETGEAR JNR1010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for this issue is CVE-2016-11015.
The severity of CVE-2016-11015 is medium, with a severity value of 6.5.
CVE-2016-11015 is a vulnerability in NETGEAR JNR1010 devices before 1.0.0.32 that allows CGI-bin/webproc CSRF via the InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
NETGEAR JNR1010 devices with firmware versions up to 1.0.0.32 are affected by CVE-2016-11015.
To fix CVE-2016-11015, users should update their NETGEAR JNR1010 devices to firmware version 1.0.0.32 or later.