CVE-2020-11769: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBK50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11769?
CVE-2020-11769 has a moderate severity rating due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2020-11769?
To fix CVE-2020-11769, users should update their NETGEAR devices to the latest firmware version as referenced in the security advisory.
Which NETGEAR devices are affected by CVE-2020-11769?
CVE-2020-11769 affects several NETGEAR devices including D7800, R7500v2, R7800, R8900, R9000, RAX120, RBR20, RBS20, RBK20, and others listed in the vulnerability report.
What is stored XSS in the context of CVE-2020-11769?
Stored XSS in CVE-2020-11769 refers to the vulnerability allowing an attacker to inject malicious scripts that are saved and executed when other users access the compromised devices.
What versions of firmware are vulnerable to CVE-2020-11769?
The vulnerable firmware versions for CVE-2020-11769 include D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, and others as detailed in the advisory.