Command Injection Vulnerability in NETGEAR Routers and Gateways
CVE-2019-20702

6.3MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
16 April 2020

Summary

Certain NETGEAR routers and gateways are vulnerable to a command injection attack. This allows an authenticated user to execute arbitrary commands on the affected device, potentially leading to unauthorized access and exploitation. The impacted products are the D3600, D6000, and XR500, which must be updated to specific versions to mitigate this risk. Organizations using these devices should promptly apply the available security updates to safeguard their networks.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.