Administrative Credential Disclosure Vulnerability in NETGEAR MR1100 Devices
CVE-2019-20638

7HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
15 April 2020

Summary

The NETGEAR MR1100 devices, prior to the version 12.06.08.00, are susceptible to a vulnerability that allows unauthorized disclosure of administrative credentials. This could potentially allow an attacker to gain access to sensitive configurations and system controls, leading to further exploitation. Users are recommended to upgrade their devices to the latest firmware version to mitigate the risk of this security issue. For more details, refer to the security advisory issued by NETGEAR.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.