CVE-2024-36788: Medium severity netgear wgr614 firmware vulnerability
Netgear WNR614 JNR1010V2 N300-V1.1.0.541.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36788?
CVE-2024-36788 has a medium severity rating due to the potential for attackers to intercept sensitive communications.
How do I fix CVE-2024-36788?
Currently, there is no official fix available for CVE-2024-36788, so users are advised to monitor for firmware updates from Netgear.
What devices are affected by CVE-2024-36788?
CVE-2024-36788 specifically affects the Netgear WNR614 router running firmware version 1.1.0.54_1.0.1.
What type of vulnerability is CVE-2024-36788?
CVE-2024-36788 is a cookie security flaw related to the improper setting of the HTTPOnly flag.
Can CVE-2024-36788 lead to a remote takeover of the device?
While CVE-2024-36788 allows for interception of communications, it does not indicate direct remote takeover capabilities.