CVE-2019-14527 is a critical command injection vulnerability affecting NETGEAR Nighthawk M1 (MR1100) devices running firmware prior to version 12.06.03, allowing authenticated attackers to execute arbitrary system commands via the web interface. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV listed as No), there is limited public exploit code and community discussion, though media coverage indicates awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.06.03CPE matchmatch criteria | cpe:2.3:o:netgear:mr1100_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.