Stored Cross-Site Scripting in NETGEAR WiFi Systems
CVE-2019-20671
6MEDIUM
Summary
Certain NETGEAR WiFi systems are susceptible to a stored cross-site scripting vulnerability that can potentially allow an attacker to execute arbitrary scripts in the context of the user's session. This affects specific models of NETGEAR devices, requiring users to update their firmware to mitigate the risk. Users are strongly advised to apply the latest firmware updates to enhance their device security and protect against these types of attacks.
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved