CVE-2019-20655: Command Injection
Published Apr 15, 2020
·Updated
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.
Affected Software
4 affected components
Netgear Xr500 Firmware<2.3.2.56
Netgear XR500
Netgear Xr700 Firmware<1.0.1.20
Netgear XR700
Event History
Apr 15, 2020
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-20655?
CVE-2019-20655 is classified as a medium severity vulnerability due to command injection by an authenticated user.
2
How do I fix CVE-2019-20655?
To fix CVE-2019-20655, you need to upgrade the firmware of affected NETGEAR XR500 to version 2.3.2.56 or XR700 to version 1.0.1.20 or later.
3
Which NETGEAR devices are affected by CVE-2019-20655?
CVE-2019-20655 affects NETGEAR XR500 devices with firmware versions prior to 2.3.2.56 and XR700 devices with versions before 1.0.1.20.
4
What type of vulnerability is CVE-2019-20655?
CVE-2019-20655 is a command injection vulnerability that can be exploited by authenticated users.
5
When was CVE-2019-20655 disclosed?
CVE-2019-20655 was disclosed in late 2019, highlighting the potential risks to users of the affected NETGEAR devices.