CVE-2020-10925: High severity Netgear R6700 firmware vulnerability
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700 V1.0.4.8410.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-9647.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10925?
CVE-2020-10925 has been rated as a medium severity vulnerability.
How do I fix CVE-2020-10925?
To fix CVE-2020-10925, update the firmware of your NETGEAR R6700 router to a version that is not affected by this vulnerability.
What types of attacks can exploit CVE-2020-10925?
CVE-2020-10925 can be exploited by network-adjacent attackers to compromise the integrity of downloaded information.
Do I need authentication to exploit CVE-2020-10925?
No, authentication is not required to exploit CVE-2020-10925.
Which NETGEAR router firmware versions are affected by CVE-2020-10925?
CVE-2020-10925 specifically affects NETGEAR R6700 firmware version 1.0.4.84_10.0.58.