| Vulnerability Name: | CVE-2019-13395 (CCN-112686) | ||||||||||||
| Assigned: | 2016-04-26 | ||||||||||||
| Published: | 2016-04-26 | ||||||||||||
| Updated: | 2020-03-18 | ||||||||||||
| Summary: | The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file. | ||||||||||||
| CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 8.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C)
8.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-352 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-13395 Source: CCN Type: Full-Disclosure Mailing List, Tue, 26 Apr 2016 07:10:35 -0400 Multiple Vulnerabilities in Voo branded Netgear CG3700b Source: XF Type: UNKNOWN netgear-cg3700b-index-csrf(112686) Source: CCN Type: Packet Storm Security [04-27-2016] Voo Branded Netgear CG3700b Firmware CSRF / Authentication Source: CCN Type: Doyler Web site Voo branded Netgear CG3700b Vulnerabilities Source: MISC Type: Exploit, Third Party Advisory https://www.doyler.net/security-not-included/voo-netgear-cg3700b-vulnerabilities Source: CCN Type: NETGEAR Web site NETGEAR | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||