First published: Thu Apr 16 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R7800 firmware | <1.0.2.60 | |
NETGEAR R7800 firmware | ||
NETGEAR XR500 firmware | <2.3.2.32 | |
NETGEAR XR500 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20706 is considered a critical vulnerability due to potential security breaches allowing command injection.
To fix CVE-2019-20706, update the firmware of NETGEAR R7800 to 1.0.2.60 or XR500 to 2.3.2.32 or later.
CVE-2019-20706 affects NETGEAR R7800 with firmware versions prior to 1.0.2.60 and XR500 with versions before 2.3.2.32.
CVE-2019-20706 is not a remote attack vulnerability; it requires authentication to exploit.
CVE-2019-20706 allows for command injection attacks by an authenticated user.