CVE-2013-3316
9.8
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.77% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-01-29 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| netgear | wnr1000 |
| netgear | wnr1000 firmware |
→ the Explorer · watch your stack · NVD