CVE-2019-17373
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
- Affected products
- Netgear Dgn2200, Netgear Dgnd3700, Netgear Mbr1515, Netgear Mbr1516, Netgear Wndr3300, Netgear Wndr3400, Netgear Wnr2000V2, Netgear Wnr3500L
- Netgear mbr1515 Firmware
- All versions
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.5% (72th percentile)
- NVD status
- Modified
- Published
- 2019-10-09
CVE-2019-17373 at NVD
No indexed exploits for CVE-2019-17373 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-17373 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.