Stored XSS Vulnerability in NETGEAR WiFi Systems
CVE-2019-20667
6MEDIUM
Summary
Certain NETGEAR devices are susceptible to a stored cross-site scripting vulnerability. This vulnerability allows an attacker to inject arbitrary web script or HTML, which can then be executed in the context of the user's web browser when they access the affected device's web interface. The devices affected include several models in the RBR, RBS, and RBK series, particularly those running versions prior to specified updates. Ensuring your devices are on the latest firmware is crucial to mitigating this security risk.
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved