CVE-2016-11015: NETGEAR JNR1010 Firmware

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.

Affected products

  • NETGEAR JNR1010 Firmware: before 1.0.0.32 (fixed in 1.0.0.32)

Published 2019-10-16. Last modified 2026-06-17.