CVE-2019-5055
published 2019-09-11CVE-2019-5055: An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70)…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.01%
78.6th percentile
An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in an invalid sequence to the service can cause a null pointer dereference, resulting in the hostapd service crashing. An unauthenticated attacker can send a specially-crafted SOAP request to trigger this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | n300_wnr2000v5 | — | — |
| netgear | wnr2000_firmware | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial-of-service vulnerabilities in some NETGEAR routers
blogs_talos·2019-09-09·CVSS 7.5
[HIGH] Vulnerability Spotlight: Denial-of-service vulnerabilities in some NETGEAR routers
## Vulnerability Spotlight: Denial-of-service vulnerabilities in some NETGEAR routers
Dave McDaniel of Cisco Talos discovered these vulnerabilities.
The NETGEAR N300 line of wireless routers contains two denial-of-service vulnerabilities. The N300 is a small and affordable wireless router that contains the basic features of a wireless router. An attacker
could exploit these bugs by sending specific SOAP and HTTP requests to different functions of the router, causing it to crash entirely.
In accordance with our coordinated disclosure policy, Cisco Talos worked with NETGEAR to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details NETGEAR N300 WNR2000v5 unauthenticated host access point daemon denial-of-service vulnerabilit
Talos
Vulnerability Spotlight: Denial-of-service vulnerabilities in some NETGEAR routers
blogs_talos·2019-09-09·CVSS 7.5
[HIGH] Vulnerability Spotlight: Denial-of-service vulnerabilities in some NETGEAR routers
Dave McDaniel of Cisco Talos discovered these vulnerabilities.
The NETGEAR N300 line of wireless routers contains two denial-of-service vulnerabilities. The N300 is a small and affordable wireless router that contains the basic features of a wireless router. An attacker
could exploit these bugs by sending specific SOAP and HTTP requests to different functions of the router, causing it to crash entirely.
In accordance with our coordinated disclosure policy, Cisco Talos worked with NETGEAR to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsNETGEAR N300 WNR2000v5 unauthenticated host access point daemon denial-of-service vulnerability (TALOS-2019-0831/CVE-2019-5054)
An exploitable denial-of-service vulnerability exist
2019-09-11
Published