CVE-2020-11771: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11771?
CVE-2020-11771 has been classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2020-11771?
To fix CVE-2020-11771, update the firmware of the affected NETGEAR devices to the latest versions beyond those specified in the vulnerability report.
Which NETGEAR devices are affected by CVE-2020-11771?
CVE-2020-11771 affects NETGEAR D7800, R7500v2, R7800, R8900, R9000, RAX120, XR500, and XR700 devices with specific firmware versions.
What type of vulnerability is CVE-2020-11771?
CVE-2020-11771 is a stored cross-site scripting (XSS) vulnerability that can allow attackers to execute scripts in the context of a user's session.
Can CVE-2020-11771 be exploited remotely?
Yes, CVE-2020-11771 can be exploited remotely by attackers who can inject malicious scripts into the web interface of affected NETGEAR devices.