CVE-2019-17373

CRITICALCVSS 9.8/10EPSS 1.54%

Last modified

CVE-2019-17373 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.. EPSS estimates a 1.54% chance of exploitation in the next 30 days.

Description

Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.54%

71.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
NetgearMbr1515 FirmwareAll versions
NetgearMbr1516 FirmwareAll versions
NetgearDgn2200 FirmwareAll versions
NetgearDgn2200m FirmwareAll versions
NetgearDgnd3700 FirmwareAll versions
NetgearWnr2000v2 FirmwareAll versions
NetgearWndr3300 FirmwareAll versions
NetgearWndr3400 FirmwareAll versions
NetgearWnr3500 FirmwareAll versions
NetgearWnr834bv2 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-17373?
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
How severe is CVE-2019-17373?
CVE-2019-17373 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.54% probability of exploitation in the next 30 days.
How do I fix CVE-2019-17373?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-17373?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST