Stored Cross-Site Scripting Vulnerability in NETGEAR Routers
CVE-2020-35840
6.9MEDIUM
Summary
Certain NETGEAR routers are susceptible to stored XSS attacks, which can allow malicious scripts to be executed on the user’s browser without their consent. This vulnerability affects specific firmware versions of various NETGEAR router models, where attackers may exploit this flaw to inject harmful scripts during user interactions. Users running outdated firmware versions are advised to upgrade their devices to mitigate potential security risks.
References
CVSS V3.1
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved