// For flags

CVE-2019-12513

Stored XSS via DHCP Discover Request Hostname

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname field, an attacker may execute stored XSS attacks against this device. When the malicious DHCP request is received, the device will generate a log entry containing the malicious hostname. This log entry may then be viewed at Advanced settings->Administration->Logs to trigger the exploit. Although this value is inserted into a textarea tag, converted to all-caps, and limited in length, attacks are still possible.

En NETGEAR Nighthawk X10-R900 versiones anteriores a 1.0.4.24, mediante el envío de una petición de detección de DHCP que contiene un campo hostname malicioso, un atacante puede ejecutar ataques de tipo XSS almacenado contra este dispositivo. Cuando es recibida una petición DHCP maliciosa, el dispositivo generará una entrada de registro que contiene el hostname malicioso. Esta entrada de registro puede entonces ser visualizada en Advanced settings-)Administration-)Logs para activar la explotación. Aunque este valor es insertado en una textarea tag, converted to all-caps, y limited in length, los ataques aún son posibles.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-06-01 CVE Reserved
  • 2020-02-24 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netgear
Search vendor "Netgear"
Nighthawk X10-r9000 Firmware
Search vendor "Netgear" for product "Nighthawk X10-r9000 Firmware"
< 1.0.4.24
Search vendor "Netgear" for product "Nighthawk X10-r9000 Firmware" and version " < 1.0.4.24"
-
Affected
in Netgear
Search vendor "Netgear"
Nighthawk X10-r9000
Search vendor "Netgear" for product "Nighthawk X10-r9000"
--
Safe