CVE-2019-20752: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7800 before 1.0.2.58, R8900 before 1.0.4.12, R9000 before 1.0.4.12, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, WN3000RPv2 before 1.0.0.68, WN3000RPv3 before 1.0.2.70, WN3100RPv2 before 1.0.0.60, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.68.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by stored XSS vulnerability CVE-2019-20752?
The affected devices are D3600 before version 1.0.0.75, D6000 before version 1.0.0.75, D7800 before version 1.0.1.44, DM200 before version 1.0.0.58, R7800 before version 1.0.2.58, R8900 before version 1.0.4.12, R9000 before version 1.0.4.12, RBK20 before version 2.3.0.28, RBR20 before version 2.3.0.28, RBS20 before version 2.3.0.28, RBK40 before version 2.3.0.28.
What is the severity of vulnerability CVE-2019-20752?
The severity of the vulnerability is medium, with a CVSS score of 4.8.
How can I fix the stored XSS vulnerability CVE-2019-20752 on my NETGEAR device?
To fix the vulnerability, you need to update the firmware of your NETGEAR device to the latest version available.
Where can I find more information about vulnerability CVE-2019-20752?
You can find more information about the vulnerability in the Netgear Security Advisory PSV-2018-0250.
What is the CWE category of vulnerability CVE-2019-20752?
The CWE category of the vulnerability is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).