First published: Mon May 18 2020(Updated: )
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote leak of sensitive/arbitrary Wi-Fi information, such as SSIDs and Pre-Shared-Keys (PSK).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Rbs50y Firmware | =2.5.1.106 | |
Netgear Rbs50y | ||
Netgear Srr60 Firmware | =2.5.1.106 | |
Netgear Srr60 | ||
Netgear Srs60 Firmware | =2.5.1.106 | |
Netgear Srs60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11550.
The severity of CVE-2020-11550 is high (6.5).
NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106 are affected by CVE-2020-11550.
An attacker can exploit CVE-2020-11550 by leveraging the unauthenticated remote leak of sensitive/arbitrary data through the administrative SOAP interface.
Yes, it is recommended to update the affected devices to the latest firmware version provided by NETGEAR.