CVE-2019-20710: Command Injection
Published Apr 16, 2020
·Updated
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Affected Software
6 affected components
Netgear Xr500 Firmware<2.3.2.32
Netgear XR500
Netgear D3600 Firmware<1.0.0.76
Netgear D3600
Netgear D6000 Firmware<1.0.0.76
Netgear D6000
Event History
Apr 16, 2020
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverity
Frequently Asked Questions
1
Which NETGEAR devices are affected by CVE-2019-20710?
D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
2
What is the severity level of CVE-2019-20710?
The severity level of CVE-2019-20710 is high (8.0).
3
How can I fix the vulnerability in NETGEAR devices affected by CVE-2019-20710?
Update your NETGEAR device firmware to the latest version available.
4
Where can I find more information about CVE-2019-20710?
You can find more information about CVE-2019-20710 in the Netgear security advisory: https://kb.netgear.com/000061219/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Gateways-PSV-2018-0338
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-20710?
The Common Weakness Enumeration (CWE) ID for CVE-2019-20710 is 77.