CVE-2019-19494 - CVE House
Back to Database
Status published High CVE-2019-19494

Broadcom based cable modems across multiple vendors are vulnerable to...

Vulnerability Description

Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19494

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

f\@st 3890 firmware, f\@st 3686 firmware, cg3700emr firmware, c6250emr firmware, tc7230 steb firmware, 7284e firmware, 7486e firmware
Vulnerable Versions:
0, 3.428.0, 4.83.0, 2.01.03, 2.01.05, 01.25, 5.510.5.11

Timeline

Official Publish: January 9th, 2020
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.