Stored XSS Vulnerability in NETGEAR Routers and WiFi Systems
CVE-2020-35814

6.1MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
30 December 2020

Summary

Certain NETGEAR routers and WiFi systems are susceptible to stored cross-site scripting vulnerabilities, allowing attackers to inject malicious scripts. Exploitation can result in unauthorized actions performed in the context of user sessions, potentially compromising sensitive user information and device integrity. Users of D7800, R7800, R8900, R9000, RAX120, and various models in the RBK and XR series should ensure they are running the latest firmware to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.