CVE detail
CVE-2019-14526 — CVE-2019-14526
Published 2019-08-14 · Modified 2026-06-17 · Vendor netgear · Product mr1100_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0069
EPSS probability
exploitation probability, 30d
50.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References