CVE-2019-20707: Command Injection
Published Apr 16, 2020
·Updated
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
Affected Software
4 affected components
Netgear R7800 firmware<1.0.2.60
Netgear R7800
Netgear Xr500 Firmware<2.3.2.32
Netgear XR500
Event History
Apr 16, 2020
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-20707?
CVE-2019-20707 is classified as a high severity vulnerability due to the potential for authenticated command injection.
2
How do I fix CVE-2019-20707?
To mitigate CVE-2019-20707, upgrade the NETGEAR R7800 to firmware version 1.0.2.60 or higher and the XR500 to version 2.3.2.32 or higher.
3
Who is affected by CVE-2019-20707?
CVE-2019-20707 affects certain NETGEAR devices, specifically the R7800 and XR500, running vulnerable firmware versions.
4
Can CVE-2019-20707 be exploited remotely?
No, CVE-2019-20707 requires authentication, meaning an attacker must first gain access to the device.
5
What are the potential impacts of CVE-2019-20707?
Exploitation of CVE-2019-20707 can allow an authenticated user to execute arbitrary commands on the affected NETGEAR devices.