Stored XSS Vulnerability in NETGEAR Devices and Routers
CVE-2020-35806

6MEDIUM

Key Information:

Vendor

Netgear

Vendor
CVE Published:
30 December 2020

What is CVE-2020-35806?

NETGEAR devices including various routers and Orbi WiFi systems are susceptible to a stored XSS vulnerability. This issue allows an attacker to store malicious scripts within the web interface, which can be executed in the context of other users accessing the vulnerable device. The affected devices include D7800, R7500v2, R7800, RAX120, and several Orbi models among others, all of which require updates to secure against this exploit. Regular software updates are essential to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.