CVE-2020-14437: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14437?
CVE-2020-14437 has a high severity rating due to the potential for remote command injection by unauthenticated attackers.
How do I fix CVE-2020-14437?
To fix CVE-2020-14437, update the affected NETGEAR devices to firmware version 3.2.15.25 or later.
Which NETGEAR devices are affected by CVE-2020-14437?
CVE-2020-14437 affects several models, including RBK752, RBK753, RBR750, and more, all before firmware version 3.2.15.25.
Can CVE-2020-14437 be exploited remotely?
Yes, CVE-2020-14437 can be exploited remotely by unauthenticated attackers due to command injection vulnerabilities.
Is there a workaround for CVE-2020-14437 before applying the patch?
There is no specific workaround for CVE-2020-14437; applying the firmware update is the recommended solution.