Back to Database
Status published
High
CVE-2019-17049
NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in...
Vulnerability Description
NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17049
Credits & Attribution
No credits recorded in the NVD database.
More from netgear
View All →CVE-2022-48322
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by...
Unknown
0
CVE-2022-48196
Certain NETGEAR devices are affected by a buffer overflow by...
High
7.4
CVE-2022-48176
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before...
Unknown
0
CVE-2022-47052
The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi...
Unknown
0
CVE-2022-46424
An exploitable firmware modification vulnerability was discovered on the Netgear...
Unknown
0
Affected Vendor
netgear
View all reports →Affected Software
srx5308 firmware
Vulnerable Versions:
4.3.5-3
Timeline
Official Publish:
September 30th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.