CVE-2019-17372
Last modified
CVE-2019-17372 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Ac1450 Firmware | All versions |
| Netgear | D8500 Firmware | All versions |
| Netgear | Dc112a Firmware | All versions |
| Netgear | Jndr3000 Firmware | All versions |
| Netgear | Lg2200d Firmware | All versions |
| Netgear | R4500 Firmware | All versions |
| Netgear | R6200 Firmware | All versions |
| Netgear | R6200v2 Firmware | All versions |
| Netgear | R6250 Firmware | All versions |
| Netgear | R6300 Firmware | All versions |
| Netgear | R6300v2 Firmware | All versions |
| Netgear | R6400 Firmware | All versions |
| Netgear | R6700 Firmware | All versions |
| Netgear | R6900p Firmware | All versions |
| Netgear | R6900 Firmware | All versions |
| Netgear | R7000p Firmware | All versions |
| Netgear | R7000 Firmware | All versions |
| Netgear | R7100lg Firmware | All versions |
| Netgear | R7300 Firmware | All versions |
| Netgear | R7900 Firmware | All versions |
| Netgear | R8000 Firmware | All versions |
| Netgear | R8300 Firmware | All versions |
| Netgear | R8500 Firmware | All versions |
| Netgear | Wgr614v10 Firmware | All versions |
| Netgear | Wn2500rpv2 Firmware | All versions |
| Netgear | Wndr3400v2 Firmware | All versions |
| Netgear | Wndr3700v3 Firmware | All versions |
| Netgear | Wndr4000 Firmware | All versions |
| Netgear | Wndr4500 Firmware | All versions |
| Netgear | Wndr4500v2 Firmware | All versions |
| Netgear | Wnr1000 Firmware | All versions |
| Netgear | Wnr1000v3 Firmware | All versions |
| Netgear | Wnr3500l Firmware | All versions |
References
- https://github.com/zer0yu/CVE_Request/blob/master/netgear/netgear_cgi_unauthorized_access_vulnerability.mdExploit, Third Party Advisory
- https://github.com/zer0yu/CVE_Request/blob/master/netgear/netgear_cgi_unauthorized_access_vulnerability.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17372?
How severe is CVE-2019-17372?
How do I fix CVE-2019-17372?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-17367OpenWRT firmware version 18.06.4 is vulnerable to CSRF via w…8.8
- CVE-2019-17368S-CMS v1.5 has XSS in tpl.php via the member/member_login.ph…6.1
- CVE-2019-17369OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Pane…6.5
- CVE-2019-1737A vulnerability in the processing of IP Service Level Agreem…8.6
- CVE-2019-17370OTCMS v3.85 allows arbitrary PHP Code Execution because admi…7.2
- CVE-2019-17371gif2png 2.5.13 has a memory leak in the writefile function.6.5
- CVE-2019-17373Certain NETGEAR devices allow unauthenticated access to crit…9.8
- CVE-2019-17375cPanel before 82.0.15 allows API token credentials to persis…8.8
- CVE-2019-17376cPanel before 82.0.15 allows self XSS in the SSL Certificate…6.1
- CVE-2019-17377cPanel before 82.0.15 allows self XSS in LiveAPI example scr…6.1
- CVE-2019-17378cPanel before 82.0.15 allows self XSS in the SSL Key Delete …6.1
- CVE-2019-17379cPanel before 82.0.15 allows self stored XSS in the WHM SSL …6.1
Are you affected by CVE-2019-17372?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
