CVE-2019-17372: High severity netgear ac1450 firmware vulnerability
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNUaccessPasswordrecovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17372?
CVE-2019-17372 is a vulnerability that allows remote attackers to disable all authentication requirements on certain NETGEAR devices.
What is the severity of CVE-2019-17372?
The severity of CVE-2019-17372 is high with a score of 8.1.
Which NETGEAR devices are affected by CVE-2019-17372?
Affected NETGEAR devices include AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200v2, R6250, R6300, R6300v2, R6400, R6700, R6900p, R6900, R7000p, R7000, R7100lg, R7300, R7900, R8000, R8300, R8500, Wgr614v10, Wn2500rpv2, Wndr3400v2, Wndr3700v3, Wndr4000, Wndr4500, Wndr4500v2, Wnr1000, Wnr1000v3, and Wnr3500l.
How can I fix CVE-2019-17372?
Ensure that you have installed the latest firmware update provided by NETGEAR for your device.
Where can I find more information about CVE-2019-17372?
You can find more information about CVE-2019-17372 on the official GitHub page: [link](https://github.com/zer0yu/CVE_Request/blob/master/netgear/netgear_cgi_unauthorized_access_vulnerability.md).