CVE-2020-11549: High severity netgear rbs50y firmware vulnerability
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The root account has the same password as the Web-admin component. Thus, by exploiting CVE-2020-11551, it is possible to achieve remote code execution with root privileges on the embedded Linux system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue on NETGEAR devices?
The vulnerability ID of this issue on NETGEAR devices is CVE-2020-11549.
What is the severity level of CVE-2020-11549?
CVE-2020-11549 has a severity level of 8.8 (high).
Which NETGEAR devices are affected by CVE-2020-11549?
NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106 are affected by CVE-2020-11549.
What is the vulnerability in CVE-2020-11549?
The vulnerability in CVE-2020-11549 is that the root account has the same password as the Web-admin component.
Are there any fixes available for CVE-2020-11549?
Please refer to the references provided for mitigation recommendations for CVE-2020-11549.