Back to Database
Status published
Medium
CVE-2016-11015
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the...
Vulnerability Description
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-11015
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.openwall.net/full-disclosure/2016/01/11/4
- https://github.com/cybersecurityworks/Disclosed/issues/13
- https://packetstormsecurity.com/files/135215/Netgear-1.0.0.24-Cross-Site-Request-Forgery.html
- https://pmcg2k15.wordpress.com/2016/01/11/fd-cross-site-request-forgery-in-netgear-router-jnr1010-version-1-0-0-24/
- https://cybersecurityworks.com/zerodays/cve-2016-11015-netgear.html
More from netgear
View All →CVE-2022-48322
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by...
Unknown
0
CVE-2022-48196
Certain NETGEAR devices are affected by a buffer overflow by...
High
7.4
CVE-2022-48176
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before...
Unknown
0
CVE-2022-47052
The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi...
Unknown
0
CVE-2022-46424
An exploitable firmware modification vulnerability was discovered on the Netgear...
Unknown
0
Affected Vendor
netgear
View all reports →Affected Software
jnr1010 firmware
Vulnerable Versions:
0
Timeline
Official Publish:
October 16th, 2019
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.