Authentication Bypass Vulnerability on NETGEAR WNR1000V4
CVE-2019-20489

9.8CRITICAL

Key Information:

Vendor
Netgear
Vendor
CVE Published:
2 March 2020

Summary

On NETGEAR WNR1000V4 1.1.0.54 devices, a vulnerability exists in the web management interface (setup.cgi) that allows an attacker to bypass authentication. By sending specific requests without a cookie and leveraging the Set-Cookie header from the 401 Unauthorized response, an attacker can achieve remote access to the device and potentially compromise its security. This vulnerability underscores the importance of securing web management interfaces against unauthorized access attempts.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.