CSRF Vulnerability in NETGEAR Switching Hubs
CVE-2020-5621

4.3MEDIUM

What is CVE-2020-5621?

A critical security flaw exists in NETGEAR switching hubs, specifically affecting GS716Tv2 and GS724Tv3 models running firmware version 5.4.2.30 and earlier. This CSRF vulnerability enables remote adversaries to execute unauthorized actions by hijacking the authentication of legitimate administrators. By exploiting this weakness, attackers can alter device configurations without the administrator's consent, potentially compromising the security and stability of the network. It is crucial for users to update to the latest firmware to mitigate this risk.

Affected Version(s)

Multiple NETGEAR switching hubs GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.