CVE-2019-5054: Null Pointer Dereference
An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5054?
CVE-2019-5054 is rated as a high-severity denial-of-service vulnerability.
How do I fix CVE-2019-5054?
To fix CVE-2019-5054, upgrade the NETGEAR N300 (WNR2000v5) to the latest firmware version.
What devices are affected by CVE-2019-5054?
CVE-2019-5054 affects NETGEAR N300 (WNR2000v5) devices running Firmware Version V1.0.0.70.
Can CVE-2019-5054 be exploited remotely?
Yes, CVE-2019-5054 can be exploited remotely through crafted HTTP requests.
What impacts does CVE-2019-5054 have on users?
CVE-2019-5054 can lead to a denial of service, causing the device to become unresponsive.