CVE-2019-17372

HIGHCVSS 8.1/10EPSS 1.66%

Last modified

CVE-2019-17372 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. EPSS estimates a 1.66% chance of exploitation in the next 30 days.

Description

Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.66%

73.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearAc1450 FirmwareAll versions
NetgearD8500 FirmwareAll versions
NetgearDc112a FirmwareAll versions
NetgearJndr3000 FirmwareAll versions
NetgearLg2200d FirmwareAll versions
NetgearR4500 FirmwareAll versions
NetgearR6200 FirmwareAll versions
NetgearR6200v2 FirmwareAll versions
NetgearR6250 FirmwareAll versions
NetgearR6300 FirmwareAll versions
NetgearR6300v2 FirmwareAll versions
NetgearR6400 FirmwareAll versions
NetgearR6700 FirmwareAll versions
NetgearR6900p FirmwareAll versions
NetgearR6900 FirmwareAll versions
NetgearR7000p FirmwareAll versions
NetgearR7000 FirmwareAll versions
NetgearR7100lg FirmwareAll versions
NetgearR7300 FirmwareAll versions
NetgearR7900 FirmwareAll versions
NetgearR8000 FirmwareAll versions
NetgearR8300 FirmwareAll versions
NetgearR8500 FirmwareAll versions
NetgearWgr614v10 FirmwareAll versions
NetgearWn2500rpv2 FirmwareAll versions
NetgearWndr3400v2 FirmwareAll versions
NetgearWndr3700v3 FirmwareAll versions
NetgearWndr4000 FirmwareAll versions
NetgearWndr4500 FirmwareAll versions
NetgearWndr4500v2 FirmwareAll versions
NetgearWnr1000 FirmwareAll versions
NetgearWnr1000v3 FirmwareAll versions
NetgearWnr3500l FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-17372?
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
How severe is CVE-2019-17372?
CVE-2019-17372 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 1.66% probability of exploitation in the next 30 days.
How do I fix CVE-2019-17372?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-17372?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST