← Vulnerability feed

Vulnerability record · CVE-2016-11014 · published 16 October 2019

CVE-2016-11014: Netgear jnr1010 firmware insufficient session expiration vulnerability

Netgear · Jnr1010 Firmware

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

9.8 CVSS 3.1 Critical EPSS 2.5% · top 15.7% CWE-613 · Insufficient session expiration
9.8CVSS 3.1 base score, v2 7.5
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-11014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-21226Netgear jnr1010 firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1…EPSS 0.70%8.8CVE-2018-21169Netgear d7000 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7000 before 2018-03-01, D7800 before 1.0.1.31, D8…EPSS 0.63%8.8CVE-2017-18703Netgear d1500 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50,…EPSS 0.46%8.8CVE-2017-18737Netgear jnr1010 firmware injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…EPSS 1.8%8.8CVE-2017-18734Netgear jnr1010 firmware injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…EPSS 3.3%8.8CVE-2017-18749Netgear jnr1010 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 befor…EPSS 0.46%8.8CVE-2017-18764Netgear d6100 firmware injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, …EPSS 1.9%8.8CVE-2017-18781Netgear d6200 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 befor…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2016-11014), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.