CVE-2019-20486

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:wnr1000_firmware:1.1.0.54:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr1000:4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-03-02 16:15

Updated : 2024-02-28 17:28


NVD link : CVE-2019-20486

Mitre link : CVE-2019-20486

CVE.ORG link : CVE-2019-20486


JSON object : View

Products Affected

netgear

  • wnr1000_firmware
  • wnr1000
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')