← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-17373

Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:1.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
netgear mbr1515_firmware all
netgear mbr1515 all
netgear mbr1516_firmware all
netgear mbr1516 all
netgear dgn2200_firmware all
netgear dgn2200 all
netgear dgn2200m_firmware all
netgear dgn2200m all
netgear dgnd3700_firmware all
netgear dgnd3700 all
netgear wnr2000v2_firmware all
netgear wnr2000v2 all
netgear wndr3300_firmware all
netgear wndr3300 all
netgear wndr3400_firmware all
netgear wndr3400 all
netgear wnr3500_firmware all
netgear wnr3500 all
netgear wnr834bv2_firmware all
netgear wnr834bv2 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.540%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-10-09T00:00:00
Published2019-10-09T12:07:13
Last Updated2024-08-05T01:40:15

LINK COPIED TO CLIPBOARD