First published: Thu Apr 16 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R7800 firmware | <1.0.2.60 | |
NETGEAR R7800 firmware | ||
NETGEAR XR500 firmware | <2.3.2.32 | |
NETGEAR XR500 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20707 is classified as a high severity vulnerability due to the potential for authenticated command injection.
To mitigate CVE-2019-20707, upgrade the NETGEAR R7800 to firmware version 1.0.2.60 or higher and the XR500 to version 2.3.2.32 or higher.
CVE-2019-20707 affects certain NETGEAR devices, specifically the R7800 and XR500, running vulnerable firmware versions.
No, CVE-2019-20707 requires authentication, meaning an attacker must first gain access to the device.
Exploitation of CVE-2019-20707 can allow an authenticated user to execute arbitrary commands on the affected NETGEAR devices.