PT-2020-9329 · NetGear · Netgear Nighthawk X10-R900+1

Published

2020-02-24

·

Updated

2020-08-24

·

CVE-2019-12510

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: NETGEAR Nighthawk X10-R900 versions prior to 1.0.4.26
Description: The issue allows an attacker to bypass authentication checks on the device's "NETGEAR Genie" SOAP API by supplying a malicious X-Forwarded-For header with the device's LAN IP address in every request. This enables the attacker to modify almost all of the device's settings and view various configuration settings. The API endpoint affected is "/soap/server sa".
Recommendations: For versions prior to 1.0.4.26, update to version 1.0.4.26 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/soap/server sa" API endpoint until a patch is applied. Avoid using the X-Forwarded-For header with the device's LAN IP address in requests to the affected API endpoint until the issue is resolved.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12510

Affected Products

Netgear Genie
Netgear Nighthawk X10-R900