Stored XSS Vulnerability in NETGEAR Extenders and Routers
CVE-2020-26917

4.1MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
9 October 2020

Summary

Certain NETGEAR devices are susceptible to a stored XSS vulnerability that allows an attacker to inject malicious scripts. This affects multiple models, enabling unauthorized actions by leveraging the web management interface, potentially compromising user data and device integrity. Users are advised to update their devices with the latest firmware to mitigate this security risk.

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.