CSRF Vulnerability in NETGEAR Custom Firmware by Voo
CVE-2019-13395

8.8HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
13 March 2020

Summary

The Voo-branded NETGEAR CG3700b custom firmware version 2.02.03 is susceptible to Cross-Site Request Forgery (CSRF), allowing attackers to craft malicious requests that can change router configurations. This includes the ability to modify crucial settings like WEP/WPA/WPA2 keys, revert the device to factory settings, or even upload harmful configuration files, significantly compromising network security.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.