Stored Cross-Site Scripting in NETGEAR Routers
CVE-2020-35838

6.1MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
30 December 2020

Summary

Certain NETGEAR routers contain a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This can lead to unauthorized access, data theft, or further exploitation of the device. The vulnerability specifically affects various models of NETGEAR routers, which must be updated to a secure version to mitigate potential risks. For more detailed information on the affected versions and remediation, refer to NETGEAR’s security advisory.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.