CVE-2020-11550: High severity netgear rbs50y firmware vulnerability
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote leak of sensitive/arbitrary Wi-Fi information, such as SSIDs and Pre-Shared-Keys (PSK).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11550.
What is the severity of CVE-2020-11550?
The severity of CVE-2020-11550 is high (6.5).
Which products are affected by CVE-2020-11550?
NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106 are affected by CVE-2020-11550.
How can an attacker exploit CVE-2020-11550?
An attacker can exploit CVE-2020-11550 by leveraging the unauthenticated remote leak of sensitive/arbitrary data through the administrative SOAP interface.
Is there a fix available for CVE-2020-11550?
Yes, it is recommended to update the affected devices to the latest firmware version provided by NETGEAR.