Command Injection Vulnerability in NETGEAR Wireless Controllers
CVE-2020-26922

6.4MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
9 October 2020

Summary

NETGEAR has identified a command injection vulnerability affecting certain models of its wireless controllers. This weakness allows an authenticated user to execute unauthorized commands which could lead to system compromise. The issue specifically impacts the WC7500, WC7600, WC7600v2, and WC9500 models that do not meet the version requirement of 6.5.5.24. Immediate updates are recommended to enhance security and mitigate potential risks.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.