Authentication Bypass Vulnerability on NETGEAR WNR1000V4
CVE-2019-20489
9.8CRITICAL
Summary
On NETGEAR WNR1000V4 1.1.0.54 devices, a vulnerability exists in the web management interface (setup.cgi) that allows an attacker to bypass authentication. By sending specific requests without a cookie and leveraging the Set-Cookie header from the 401 Unauthorized response, an attacker can achieve remote access to the device and potentially compromise its security. This vulnerability underscores the importance of securing web management interfaces against unauthorized access attempts.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved