CVE-2019-17373: Critical severity netgear mbr1515 firmware vulnerability
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17373?
CVE-2019-17373 is a vulnerability that allows unauthenticated access to critical .cgi and .htm pages on certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2019-17373?
CVE-2019-17373 affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
How severe is CVE-2019-17373?
CVE-2019-17373 has a severity rating of 9.8 (critical).
How does CVE-2019-17373 work?
CVE-2019-17373 allows unauthenticated access to critical pages by appending a substring ending with .jpg to a URL.
Is there a fix for CVE-2019-17373?
To fix CVE-2019-17373, NETGEAR device owners should update to the latest firmware version provided by the manufacturer.