Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Mr1100_firmware
(Netgear)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 5 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-04-15 | CVE-2019-20649 | NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information. | Mr1100_firmware | 7.5 | ||
2020-04-15 | CVE-2019-20679 | NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level. | Mr1100_firmware | 9.8 | ||
2020-04-15 | CVE-2019-20638 | NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials. | Mr1100_firmware | N/A | ||
2019-08-14 | CVE-2019-14527 | An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication. | Mr1100_firmware | 9.8 | ||
2019-08-14 | CVE-2019-14526 | An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token. | Mr1100_firmware | 8.1 |