CVE-2019-19494
high · 8.8Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.
8.8
CVSS
23.1%
EPSS (exploit prob.)
98th
EPSS percentile
2020-01-09
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-120
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sagemcom | f@st_3890_firmware | < 50.10.21_t4 |
| sagemcom | f@st_3890 | all versions |
| sagemcom | f@st_3890_firmware | < 05.76.6.3f |
| sagemcom | f@st_3890 | all versions |
| sagemcom | f@st_3686_firmware | 3.428.0 |
| sagemcom | f@st_3686_firmware | 4.83.0 |
| sagemcom | f@st_3686 | all versions |
| netgear | cg3700emr_firmware | 2.01.03 |
| netgear | cg3700emr_firmware | 2.01.05 |
| netgear | cg3700emr | all versions |
| netgear | c6250emr_firmware | 2.01.03 |
| netgear | c6250emr_firmware | 2.01.05 |
| netgear | c6250emr | all versions |
| technicolor | tc7230_steb_firmware | 01.25 |
| technicolor | tc7230_steb | all versions |
| compal | 7284e_firmware | 5.510.5.11 |
| compal | 7284e | all versions |
| compal | 7486e_firmware | 5.510.5.11 |
| compal | 7486e | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://cablehaunt.com
- https://github.com/Lyrebirds/Cable-Haunt-Report/releases/download/2.4/report.pdf
- https://github.com/Lyrebirds/Fast8690-exploit
- https://www.broadcom.com
- https://cablehaunt.com
- https://github.com/Lyrebirds/Cable-Haunt-Report/releases/download/2.4/report.pdf
- https://github.com/Lyrebirds/Fast8690-exploit
- https://www.broadcom.com
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-19494