Command Injection Vulnerability in NETGEAR XR500 and XR700 Devices
CVE-2019-20655

7.3HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
15 April 2020

Summary

Certain NETGEAR devices, specifically the XR500 and XR700 models, are susceptible to command injection vulnerabilities when an authenticated user accesses them. This flaw allows attackers to execute arbitrary commands on the affected devices, potentially compromising device integrity and network security. The vulnerability impacts XR500 devices running firmware versions prior to 2.3.2.56 and XR700 devices running versions before 1.0.1.20, making it crucial for users to apply the latest security updates as soon as possible.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.