← Back to browse · API

CVE-2019-5016

Severity
CRITICAL
CVSS
10.0
EPSS
0.03562
Risk score
41.25
CISA KEV
No
PoC
No
Published
2019-06-17
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14623, GHSA-QXR6-VHX6-6R6G
Products
Talos:KCodes NETGEAR Nighthawk AC3000 (R7900) Firmware Version V1.0.3.810.0.37 (11/1/18) - NetUSB.ko 1.0.2.69, Talos:KCodes NETGEAR Nighthawk AC3200 (R8000) Firmware Version V1.0.4.2810.1.54 (11/7/18) - NetUSB.ko 1.0.2.66
Sources
euvd EUVD-2019-14623

Description

An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potentially several other vendors/products. A specially crafted index value can cause an invalid memory read, resulting in a denial of service or remote information disclosure. An unauthenticated attacker can send a crafted packet on the local network to trigger this vulnerability.

References