Access Control Flaw in NETGEAR MR1100 Devices
CVE-2019-20679

7.3HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
15 April 2020

Summary

The NETGEAR MR1100 devices prior to version 12.06.08.00 are susceptible to a security issue stemming from the absence of adequate access control at the function level. This vulnerability enables unauthorized users to potentially gain access to sensitive functions that should be secured, posing a risk to the overall integrity of the device and its data. It is crucial for users of affected devices to apply the latest firmware updates to mitigate this vulnerability.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.