CVE-2019-20674: XSS
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
Affected Software
Event History
Frequently Asked Questions
What devices are affected by CVE-2019-20674?
The vulnerability affects NETGEAR RBR20, RBS20, RBK20, RBR40, RBS40, RBK40, RBR50, RBS50, and RBK50 devices running specific firmware versions before the designated updates.
What is the severity of CVE-2019-20674?
CVE-2019-20674 has been classified as having moderate severity due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2019-20674?
To address CVE-2019-20674, upgrade the affected NETGEAR device firmware to the latest version indicated in the advisory.
What is stored XSS in relation to CVE-2019-20674?
Stored XSS refers to a vulnerability where an attacker can store malicious scripts in the device, which are then executed when accessed by users.
What should I do if I cannot update my NETGEAR device for CVE-2019-20674?
If updating is not possible, consider isolating the device from sensitive networks and regularly monitoring for unusual activities.