CVE-2019-12510 Information
Feb 14, 2021
cve
Description
In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26 an attacker may bypass all authentication checks on the device’s \NETGEAR Genie\ SOAP API (/soap/server_sa) by supplying a malicious X-Forwarded-For header of the device’s LAN IP address (192.168.1.1) in every request. As a result an attacker may modify almost all of the device’s settings and view various configuration settings.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Reference
https://www.ise.io/casestudies/sohopelessly-broken-2-0/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
9.1
Share on: