CVE-2019-12510 is a critical authentication bypass vulnerability affecting NETGEAR Nighthawk X10-R9000 routers prior to firmware version 1.0.4.26. An unauthenticated attacker can bypass all authentication checks on the device's SOAP API by manipulating the X-Forwarded-For header with the device's LAN IP address. This allows for full control over device settings and access to configuration data. With a CVSS score of 9.1 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality and integrity. While there is no evidence of active exploitation, no public exploit code, and minimal community discussion, the high FAUCET Risk Score of 72/100 indicates its significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.4.26CPE matchmatch criteria | cpe:2.3:o:netgear:nighthawk_x10-r9000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.