Vulnerability Details CVE-2019-14526
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.2%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.8
Products affected by CVE-2019-14526
-
cpe:2.3:h:netgear:mr1100:-
-
cpe:2.3:o:netgear:mr1100_firmware:-
-
cpe:2.3:o:netgear:mr1100_firmware:12.05.05.00