High severity8.8NVD Advisory· Published Jan 9, 2020· Updated Jun 17, 2026
CVE-2019-19494
CVE-2019-19494
Description
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- Range: STEB 01.25
- Broadcom/cable modemsdescription
- cpe:2.3:o:sagemcom:f\@st_3890_firmware:*:*:*:*:*:*:*:*Range: <50.10.21_t4
cpe:2.3:o:sagemcom:f\@st_3686_firmware:3.428.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:sagemcom:f\@st_3686_firmware:3.428.0:*:*:*:*:*:*:*
- cpe:2.3:o:sagemcom:f\@st_3686_firmware:4.83.0:*:*:*:*:*:*:*
cpe:2.3:o:netgear:cg3700emr_firmware:2.01.03:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:netgear:cg3700emr_firmware:2.01.03:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:cg3700emr_firmware:2.01.05:*:*:*:*:*:*:*
cpe:2.3:o:netgear:c6250emr_firmware:2.01.03:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:netgear:c6250emr_firmware:2.01.03:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:c6250emr_firmware:2.01.05:*:*:*:*:*:*:*
- cpe:2.3:o:technicolor:tc7230_steb_firmware:01.25:*:*:*:*:*:*:*
- cpe:2.3:o:compal:7284e_firmware:5.510.5.11:*:*:*:*:*:*:*
- cpe:2.3:o:compal:7486e_firmware:5.510.5.11:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- cablehaunt.comnvdExploitTechnical DescriptionThird Party Advisory
- github.com/Lyrebirds/Cable-Haunt-Report/releases/download/2.4/report.pdfnvdTechnical DescriptionThird Party Advisory
- www.broadcom.comnvdProduct
News mentions
0No linked articles in our index yet.