First published: Thu May 28 2020(Updated: )
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6120 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR R6120 | ||
Netgear R6220 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR R6220 | ||
Netgear R6350 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear R6350 | ||
Netgear R6400 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR R6400 | ||
NETGEAR R6400 | =v2 | |
Netgear R6800 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear R6800 | ||
Netgear R6850 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear R6850 | ||
Netgear R7000p Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear R7000P | ||
NETGEAR R7800 firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR R7800 | ||
Netgear R8000 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR R8000 | ||
Netgear R9000 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR R9000 | ||
Netgear Rax120 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear Rax120 | ||
Netgear Rbr20 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear Rbr20 | ||
Netgear Xr300 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
Netgear XR300 | ||
Netgear Xr500 Firmware | >=v1.0.9.6_1.2.19<=v1.0.11.100_10.2.100 | |
NETGEAR XR500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13245 is a vulnerability that affects certain NETGEAR devices and allows attackers to bypass SSL certificate validation.
CVE-2020-13245 affects NETGEAR devices R7000, R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.
The severity of CVE-2020-13245 is medium with a CVSS score of 5.9.
To fix CVE-2020-13245, ensure that your NETGEAR device is running the latest firmware version provided by the manufacturer.
You can find more information about CVE-2020-13245 on the official NETGEAR website and the IoT Lab FH OOe GitHub page.