CVE-2019-20706: Command Injection
Published Apr 16, 2020
·Updated
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
Affected Software
4 affected components
Netgear R7800 firmware<1.0.2.60
Netgear R7800
Netgear Xr500 Firmware<2.3.2.32
Netgear XR500
Event History
Apr 16, 2020
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-20706?
CVE-2019-20706 is considered a critical vulnerability due to potential security breaches allowing command injection.
2
How do I fix CVE-2019-20706?
To fix CVE-2019-20706, update the firmware of NETGEAR R7800 to 1.0.2.60 or XR500 to 2.3.2.32 or later.
3
Which NETGEAR devices are affected by CVE-2019-20706?
CVE-2019-20706 affects NETGEAR R7800 with firmware versions prior to 1.0.2.60 and XR500 with versions before 2.3.2.32.
4
Is CVE-2019-20706 a remote attack vulnerability?
CVE-2019-20706 is not a remote attack vulnerability; it requires authentication to exploit.
5
What type of attack does CVE-2019-20706 allow?
CVE-2019-20706 allows for command injection attacks by an authenticated user.