CVE-2019-20659: Command Injection
Published Apr 15, 2020
·Updated
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
Affected Software
10 affected components
Netgear R6400 Firmware<1.0.4.84
Netgear R6400=v2
Netgear R6700 firmware<1.0.2.8
Netgear R6700
Netgear R6700 firmware<1.0.4.84
Netgear R6700=v3
Netgear R6900 Firmware<1.0.2.8
Netgear R6900
Netgear R7900 Firmware<1.0.3.10
Netgear R7900
Event History
Apr 15, 2020
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
DescriptionSeverity
Frequently Asked Questions
1
What devices are affected by CVE-2019-20659?
CVE-2019-20659 affects NETGEAR R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
2
What is the severity of CVE-2019-20659?
CVE-2019-20659 has a high severity level due to its potential for command injection by authenticated users.
3
How do I fix CVE-2019-20659?
To fix CVE-2019-20659, update your device firmware to the latest version provided by NETGEAR.
4
What type of vulnerability is CVE-2019-20659?
CVE-2019-20659 is classified as a command injection vulnerability.
5
Can CVE-2019-20659 be exploited remotely?
No, CVE-2019-20659 can only be exploited by an authenticated user with access to the affected NETGEAR devices.