CVE-2019-14527: OS Command Injection
Published Aug 14, 2019
·Updated
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.
Affected Software
2 affected components
Netgear Mr1100 Firmware<12.06.03
Netgear MR1100
Event History
Aug 14, 2019
CVE Published
via MITRE·08:51 PM
Data Sourced
via MITRE·08:51 PM
Description
Invalid Date
News Published
Invalid Date
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2019-14527?
CVE-2019-14527 is rated as high severity due to the potential for unauthorized system command execution.
2
How do I fix CVE-2019-14527?
To fix CVE-2019-14527, update the firmware of your NETGEAR Nighthawk M1 device to version 12.06.03 or later.
3
Who is affected by CVE-2019-14527?
Users of the NETGEAR Nighthawk M1 (MR1100) device running firmware versions prior to 12.06.03 are affected by CVE-2019-14527.
4
What type of vulnerability is CVE-2019-14527?
CVE-2019-14527 is a command injection vulnerability that can be exploited via the web interface.
5
Can CVE-2019-14527 be exploited remotely?
Yes, CVE-2019-14527 can be exploited remotely after gaining access to the web interface of the device.