Stored Cross-Site Scripting Vulnerability in NETGEAR Routers
CVE-2020-35811

6.1MEDIUM

Key Information:

Vendor

Netgear

Vendor
CVE Published:
30 December 2020

What is CVE-2020-35811?

NETGEAR routers, including various models, are susceptible to a stored cross-site scripting vulnerability that could allow an attacker to inject malicious scripts. This security flaw affects multiple firmware versions and highlights the critical need for timely updates to ensure network safety. If exploited, this vulnerability may enable attackers to execute scripts in the context of the user’s web session, potentially compromising sensitive information. Users are encouraged to upgrade to the latest firmware to mitigate this risk. For more information, refer to the NETGEAR security advisory.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.