CVE-2019-13395: NETGEAR CG3700B Firmware
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.
Affected products
- NETGEAR CG3700B Firmware: version 2.02.03 only
Published 2020-03-13. Last modified 2026-06-17.