Stored XSS Vulnerability in NETGEAR Routers and WiFi Products
CVE-2020-35809
6.1MEDIUM
Summary
Certain NETGEAR routers and WiFi products are susceptible to a stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject malicious scripts into the web interface accessible by users. This vulnerability affects multiple router models running firmware versions prior to their respective safe versions, potentially compromising user sessions or sensitive information. Users should update their devices to secure versions to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved