First published: Wed Apr 15 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R6400 firmware | <1.0.4.84 | |
NETGEAR R6400 firmware | =v2 | |
NETGEAR R6700 firmware | <1.0.2.8 | |
NETGEAR R6700v1 firmware | ||
NETGEAR R6700 firmware | <1.0.4.84 | |
NETGEAR R6700v1 firmware | =v3 | |
Netgear R6900 Firmware | <1.0.2.8 | |
Netgear R6900 Firmware | ||
NETGEAR R7900P firmware | <1.0.3.10 | |
NETGEAR R7900P firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20659 affects NETGEAR R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
CVE-2019-20659 has a high severity level due to its potential for command injection by authenticated users.
To fix CVE-2019-20659, update your device firmware to the latest version provided by NETGEAR.
CVE-2019-20659 is classified as a command injection vulnerability.
No, CVE-2019-20659 can only be exploited by an authenticated user with access to the affected NETGEAR devices.