PoC Index

CVE-2024-36788

MEDIUM 5.9EPSS 0.3%

Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v3.1
5.9 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
0.27% chance of exploitation in the next 30 days, 19th percentile
Published
2024-06-07
Updated
2025-02-13

Proof-of-concept exploits (1)

References

Related