CVE-2019-20703: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20703?
CVE-2019-20703 has a high severity due to the potential for command injection by an authenticated user.
How do I fix CVE-2019-20703?
To fix CVE-2019-20703, update your NETGEAR D3600, D6000, or XR500 devices to their respective firmware versions 1.0.0.76 or 2.3.2.32.
Which NETGEAR devices are affected by CVE-2019-20703?
The affected NETGEAR devices include D3600 firmware versions before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Can CVE-2019-20703 be exploited remotely?
No, CVE-2019-20703 requires authentication, meaning that a user must already have access to the device.
What are the implications of CVE-2019-20703 for users?
Users of affected NETGEAR devices risk unauthorized command execution, potentially allowing an attacker to gain control over the device.