CVE-2019-20486

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:wnr1000_firmware:1.1.0.54:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr1000:4:*:*:*:*:*:*:*

History

21 Nov 2024, 04:38

Type Values Removed Values Added
References () https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/august/the-netgear-wnr1000v4-round-2/ - Exploit, Third Party Advisory () https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/august/the-netgear-wnr1000v4-round-2/ - Exploit, Third Party Advisory

Information

Published : 2020-03-02 16:15

Updated : 2024-11-21 04:38


NVD link : CVE-2019-20486

Mitre link : CVE-2019-20486

CVE.ORG link : CVE-2019-20486


JSON object : View

Products Affected

netgear

  • wnr1000
  • wnr1000_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')