Stored XSS Vulnerability in NETGEAR Routers
CVE-2020-35841

6.9MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
30 December 2020

Summary

Certain NETGEAR devices are susceptible to a stored Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts. This risk affects a range of models and can be exploited by an authorized user, potentially compromising users' sensitive information or allowing unauthorized actions to be executed within the context of the affected device's web management interface. It is critical for users to ensure their devices are updated to the latest firmware to mitigate this security risk.

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.