Remote Authentication Bypass Vulnerability in NETGEAR Devices
CVE-2019-17372
8.1HIGH
What is CVE-2019-17372?
Certain NETGEAR devices are susceptible to a remote authentication bypass vulnerability that allows attackers to disable all authentication requirements via the genieDisableLanChanged.cgi endpoint. Following this, attackers can access sensitive pages such as MNU_accessPassword_recovered.html to retrieve a valid admin password. This vulnerability can lead to unauthorized access and control over the affected devices, potentially compromising the entire network.