CVE-2019-12510 Information

Description

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26 an attacker may bypass all authentication checks on the device’s \NETGEAR Genie\ SOAP API (/soap/server_sa) by supplying a malicious X-Forwarded-For header of the device’s LAN IP address (192.168.1.1) in every request. As a result an attacker may modify almost all of the device’s settings and view various configuration settings.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Reference

https://www.ise.io/casestudies/sohopelessly-broken-2-0/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

NONE

Base Severity

9.1

Share on: