Stored XSS Vulnerability in NETGEAR WiFi Systems
CVE-2019-20667

6MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
15 April 2020

Summary

Certain NETGEAR devices are susceptible to a stored cross-site scripting vulnerability. This vulnerability allows an attacker to inject arbitrary web script or HTML, which can then be executed in the context of the user's web browser when they access the affected device's web interface. The devices affected include several models in the RBR, RBS, and RBK series, particularly those running versions prior to specified updates. Ensuring your devices are on the latest firmware is crucial to mitigating this security risk.

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.