CVE-2019-20704: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20704?
CVE-2019-20704 is a vulnerability that allows command injection by an authenticated user on certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2019-20704?
CVE-2019-20704 affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
How severe is CVE-2019-20704?
CVE-2019-20704 has a severity rating of high.
How can I fix CVE-2019-20704?
To fix CVE-2019-20704, users should update their NETGEAR devices to the specified firmware versions: D3600 to 1.0.0.76 or higher, D6000 to 1.0.0.76 or higher, and XR500 to 2.3.2.32 or higher.
Where can I find more information about CVE-2019-20704?
You can find more information about CVE-2019-20704 in the security advisory published by NETGEAR: [link](https://kb.netgear.com/000061225/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Gateways-PSV-2018-0392).