First published: Thu Apr 16 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Xr500 Firmware | <2.3.2.32 | |
NETGEAR XR500 | ||
Netgear D3600 Firmware | <1.0.0.76 | |
NETGEAR D3600 | ||
Netgear D6000 Firmware | <1.0.0.76 | |
Netgear D6000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20704 is a vulnerability that allows command injection by an authenticated user on certain NETGEAR devices.
CVE-2019-20704 affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
CVE-2019-20704 has a severity rating of high.
To fix CVE-2019-20704, users should update their NETGEAR devices to the specified firmware versions: D3600 to 1.0.0.76 or higher, D6000 to 1.0.0.76 or higher, and XR500 to 2.3.2.32 or higher.
You can find more information about CVE-2019-20704 in the security advisory published by NETGEAR: [link](https://kb.netgear.com/000061225/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Gateways-PSV-2018-0392).