
CVE-2019-20488
https://notcve.org/view.php?id=CVE-2019-20488
02 Mar 2020 — An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter. Se detectó un problema en los dispositivos NETGEAR WNR1000V4 versión 1.1.0.54. Múltiples acciones dentro de la interfaz de administración web (setup.cgi) son vulnerables a una inyección de comandos, permitiendo a atacante... • https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/august/the-netgear-wnr1000v4-round-2 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2019-20489
https://notcve.org/view.php?id=CVE-2019-20489
02 Mar 2020 — An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a cookie, reads the Set-Cookie header in the 401 Unauthorized response, and then repeats the FW_remote.htm&todo=cfg_init request with the specified cookie. Se detectó un problema en los dispositivos N... • https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/august/the-netgear-wnr1000v4-round-2 • CWE-287: Improper Authentication •

CVE-2019-20487
https://notcve.org/view.php?id=CVE-2019-20487
02 Mar 2020 — An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI. Se detectó un problema en los dispositivos NETGEAR WNR1000V4 versión 1.1.0.54. Múltiples acciones dentro de la consola de administración web de WNR1000V4 son vulnerables a una petición GET no autenticada (explotable directamente o por medi... • https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/august/the-netgear-wnr1000v4-round-2 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-3317
https://notcve.org/view.php?id=CVE-2013-3317
29 Jan 2020 — Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. Netgear WNR1000v3 con versiones de firmware anteriores a 1.0.2.60, contiene una Omisión de Autenticación por medio de la tecla NtgrBak. • http://www.exploit-db.com/exploits/24916 • CWE-287: Improper Authentication •

CVE-2013-3316
https://notcve.org/view.php?id=CVE-2013-3316
29 Jan 2020 — Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". Netgear WNR1000v3 con versiones de firmware anteriores a 1.0.2.60, contiene una Omisión de Autenticación debido a que el servidor omite las comprobaciones para las URL que contienen una extensión ".jpg". • http://www.exploit-db.com/exploits/24916 • CWE-287: Improper Authentication •

CVE-2019-17372
https://notcve.org/view.php?id=CVE-2019-17372
09 Oct 2019 — Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, ... • https://github.com/zer0yu/CVE_Request/blob/master/netgear/netgear_cgi_unauthorized_access_vulnerability.md • CWE-287: Improper Authentication •