Severity
9.8CRITICAL
EPSS
0.5%
top 34.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Latest updateMay 24

Description

NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDnetgear/mr1100_firmware< 12.06.08.00

🔴Vulnerability Details

2
GHSA
GHSA-5mp8-4qmg-75h8: NETGEAR MR1100 devices before 122022-05-24
CVEList
CVE-2019-20679: NETGEAR MR1100 devices before 122020-04-15

📋Vendor Advisories

1
Red Hat
busybox: Out of bounds read in udhcp components resulting in information disclosure2019-01-09

💬Community

1
Bugzilla
CVE-2019-5747 busybox: Out of bounds read in udhcp components resulting in information disclosure2019-01-17
CVE-2019-20679 (CRITICAL CVSS 9.8) | NETGEAR MR1100 devices before 12.06 | cvebase.io