First published: Wed Apr 15 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR XR500 firmware | <2.3.2.56 | |
NETGEAR XR500 firmware | ||
NETGEAR XR700 | <1.0.1.20 | |
NETGEAR XR700 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20655 is classified as a medium severity vulnerability due to command injection by an authenticated user.
To fix CVE-2019-20655, you need to upgrade the firmware of affected NETGEAR XR500 to version 2.3.2.56 or XR700 to version 1.0.1.20 or later.
CVE-2019-20655 affects NETGEAR XR500 devices with firmware versions prior to 2.3.2.56 and XR700 devices with versions before 1.0.1.20.
CVE-2019-20655 is a command injection vulnerability that can be exploited by authenticated users.
CVE-2019-20655 was disclosed in late 2019, highlighting the potential risks to users of the affected NETGEAR devices.