CVE-2020-14438: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14438?
CVE-2020-14438 is a vulnerability that allows an unauthenticated attacker to execute commands on certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2020-14438?
RBK752, RBK753, RBK753S, RBR750, RBS750, RBK842, RBR840, and RBS840 are affected by CVE-2020-14438.
What is the severity of CVE-2020-14438?
CVE-2020-14438 has a severity rating of critical, with a CVSS score of 8.8.
How can an unauthenticated attacker exploit CVE-2020-14438?
An unauthenticated attacker can exploit CVE-2020-14438 by injecting malicious commands into vulnerable NETGEAR devices.
Is there a fix for CVE-2020-14438?
Yes, updating the firmware of affected NETGEAR devices to version 3.2.15.25 or later fixes CVE-2020-14438.