Vulnerabilities > CVE-2016-11058 - Insufficient Session Expiration vulnerability in Netgear Genie

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
netgear
CWE-613

Summary

The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.

Vulnerable Configurations

Part Description Count
Application
Netgear
1

Common Weakness Enumeration (CWE)