First published: Mon Mar 02 2020(Updated: )
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Wnr1000 Firmware | =1.1.0.54 | |
Netgear WNR1000 | =4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-20488.
The severity of CVE-2019-20488 is critical, with a CVSS score of 9.8.
The affected software for CVE-2019-20488 is Netgear WNR1000V4 firmware version 1.1.0.54.
CVE-2019-20488 allows remote attackers to execute arbitrary commands on NETGEAR WNR1000V4 devices.
Unfortunately, there is no fix available for CVE-2019-20488 at the moment. It is recommended to apply any security patches or updates provided by the vendor.