NetGear · Netgear Srx5308 · CVE-2019-17049
**Name of the Vulnerable Software and Affected Versions**
NETGEAR SRX5308 version 4.3.5-3
**Description**
The issue allows for SQL Injection, which has been exploited in the wild. In September 2019, this was used to add a new user account.
**Recommendations**
For NETGEAR SRX5308 version 4.3.5-3, update to a version that contains a fix for this issue, as the current version is affected by SQL Injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.