CVE-2019-17049

NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.

Basic Information

CVE State
PUBLISHED
Reserved Date
September 30, 2019
Published Date
September 30, 2019
Last Updated
August 05, 2024
Vendor
NETGEAR
Product
SRX5308
Description
NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.
Tags
edge

CVSS Scores

CVSS v3.1

7.5 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Exploit Status

Exploited in the Wild
Yes (2019-09-30 18:37:21 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2019-09-30 18:37:21 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel