First published: Wed Apr 15 2020(Updated: )
Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR D7800 | <1.0.1.56 | |
NETGEAR D7800 Firmware | ||
NETGEAR R7500v2 firmware | <1.0.3.46 | |
NETGEAR R7500v2 firmware | =v2 | |
NETGEAR R7800 firmware | <1.0.2.68 | |
NETGEAR R7800 firmware | ||
NETGEAR R8900 firmware | <1.0.4.28 | |
NETGEAR R8900 | ||
NETGEAR R9000 firmware | <1.0.4.28 | |
NETGEAR R9000 firmware | ||
NETGEAR RAX120 firmware | <1.0.0.78 | |
NETGEAR RAX120 firmware | ||
NETGEAR XR500 firmware | <2.3.2.56 | |
NETGEAR XR500 firmware | ||
NETGEAR XR700 | <1.0.1.10 | |
NETGEAR XR700 firmware | ||
NETGEAR RBR20 | <2.3.5.26 | |
NETGEAR RBR20 | ||
NETGEAR RBS20 | <2.3.5.26 | |
NETGEAR RBS20 firmware | ||
NETGEAR RBK20 Router Firmware | <2.3.5.26 | |
NETGEAR Orbi RBK20 | ||
NETGEAR CBR40 firmware | <2.3.5.30 | |
NETGEAR RBR40 firmware | ||
NETGEAR RBS40 Firmware | <2.3.5.30 | |
NETGEAR RBS40 firmware | ||
NETGEAR RBK40 Satellite Firmware | <2.3.5.30 | |
NETGEAR RBK40 firmware | ||
NETGEAR RBR50 firmware | <2.3.5.30 | |
NETGEAR RBR50 firmware | ||
NETGEAR RBS50 Firmware | <2.3.5.30 | |
NETGEAR RBS50 | ||
NETGEAR RBK50 firmware | <2.3.5.30 | |
NETGEAR Orbi RBK50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-11768 is classified as medium due to its potential for stored cross-site scripting (XSS) vulnerabilities that could allow attackers to execute scripts in the context of the affected application.
To fix CVE-2020-11768, users should update their NETGEAR devices to the latest firmware versions specified in the advisory.
CVE-2020-11768 affects several NETGEAR devices including D7800, R7500v2, R7800, R8900, and R9000, among others.
Stored cross-site scripting refers to a vulnerability where an attacker can inject malicious scripts that are stored on the server and executed by users when they access affected pages.
Attackers could exploit CVE-2020-11768 to steal session cookies or other sensitive information from users who access the compromised interface of affected NETGEAR devices.