Stored Cross-Site Scripting Vulnerability in NETGEAR WiFi Systems
CVE-2019-20674
6MEDIUM
Summary
Certain NETGEAR WiFi systems are affected by a stored Cross-Site Scripting (XSS) vulnerability. This issue allows an attacker to inject malicious scripts into the affected devices, which may be executed in the context of users accessing the compromised pages. The vulnerability affects specific versions of devices such as the RBR20, RBK20, and others, potentially leading to unauthorized actions or data exposure.
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved