CVE-2019-20691Cross-Site Request Forgery in Netgear D3600 Firmware

Severity
8.8HIGHNVD
EPSS
0.2%
top 56.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 24

Description

Certain NETGEAR devices are affected by CSRF. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.24, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150v1 before 1.0.0.42, EX6200 before 1.0.3.88, EX7000 before 1.0.0.66, and WN2500RPv2 before 1.0.1.54.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages12 packages

NVDnetgear/d3600_firmware< 1.0.0.72
NVDnetgear/d6000_firmware< 1.0.0.72
NVDnetgear/ex3700_firmware< 1.0.0.70
NVDnetgear/ex3800_firmware< 1.0.0.70
NVDnetgear/ex6000_firmware< 1.0.0.30

🔴Vulnerability Details

2
GHSA
GHSA-wh8w-v6q4-fgcv: Certain NETGEAR devices are affected by CSRF2022-05-24
CVEList
CVE-2019-20691: Certain NETGEAR devices are affected by CSRF2020-04-16
CVE-2019-20691 — Cross-Site Request Forgery in Netgear | cvebase