Authentication Bypass Vulnerability on NETGEAR WNR1000V4
CVE-2019-20489
9.8CRITICAL
What is CVE-2019-20489?
On NETGEAR WNR1000V4 1.1.0.54 devices, a vulnerability exists in the web management interface (setup.cgi) that allows an attacker to bypass authentication. By sending specific requests without a cookie and leveraging the Set-Cookie header from the 401 Unauthorized response, an attacker can achieve remote access to the device and potentially compromise its security. This vulnerability underscores the importance of securing web management interfaces against unauthorized access attempts.