First published: Wed Apr 15 2020(Updated: )
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR RBR50 firmware | <2.3.5.30 | |
NETGEAR RBR50 firmware | ||
NETGEAR RBS50 Firmware | <2.3.5.30 | |
NETGEAR RBS50 Firmware | ||
NETGEAR RBK50 firmware | <2.3.5.30 | |
NETGEAR Orbi RBK50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20666 is classified as a moderate severity vulnerability due to the stored XSS risks it poses.
To mitigate CVE-2019-20666, you should upgrade your NETGEAR RBR50, RBS50, or RBK50 device firmware to version 2.3.5.30 or later.
CVE-2019-20666 affects NETGEAR RBR50, RBS50, and RBK50 devices running firmware versions prior to 2.3.5.30.
Stored XSS in CVE-2019-20666 allows attackers to inject malicious scripts that are then executed when users access the affected device's interface.
Yes, you can check your firmware version through the device interface to determine if it's affected by CVE-2019-20666.