Stored Cross-Site Scripting Vulnerability in NETGEAR Devices
CVE-2020-35842
6.9MEDIUM
Summary
Certain NETGEAR router models are susceptible to stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the web interface. This vulnerability impacts various device models, including the D6200, D7000, and others, prior to their respective firmware updates. If exploited, this flaw could enable malicious actors to execute harmful scripts in the context of the user's session or steal sensitive information. Users are advised to update their devices to mitigate potential security risks.
References
CVSS V3.1
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved