← Back to CVE List

CVE-2019-14526

Published: 2019-08-14T21:15Z
Last Modified: 2024-11-21T04:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt