CVE-2019-14526

Severity
8.1HIGH
EPSS
0.2%
top 63.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 14
Latest updateMay 24

Description

An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages1 packages

NVDnetgear/mr1100_firmware< 12.06.03

🔴Vulnerability Details

2
GHSA
GHSA-76g9-9frm-pxr6: An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 122022-05-24
CVEList
CVE-2019-14526: An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 122019-08-14
CVE-2019-14526 (HIGH CVSS 8.1) | An issue was discovered on NETGEAR | cvebase.io