CVE-2020-25067: Command Injection
Published Sep 1, 2020
·Updated
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
Affected Software
2 affected components
Netgear R8300 Firmware<1.0.2.134
Netgear R8300
Event History
Sep 1, 2020
CVE Published
via MITRE·03:22 AM
Data Sourced
via MITRE·03:22 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2020-25067?
CVE-2020-25067 is a vulnerability in NETGEAR R8300 devices before 1.0.2.134 that allows an unauthenticated attacker to perform command injection.
2
How does CVE-2020-25067 affect NETGEAR R8300 devices?
CVE-2020-25067 affects NETGEAR R8300 devices before 1.0.2.134 by allowing an unauthenticated attacker to execute arbitrary commands.
3
What is the severity of CVE-2020-25067?
CVE-2020-25067 has a severity rating of 8.8 (critical).
4
How can I fix CVE-2020-25067 on my NETGEAR R8300 device?
To fix CVE-2020-25067 on your NETGEAR R8300 device, update the firmware to version 1.0.2.134 or later.
5
Where can I find more information about CVE-2020-25067?
You can find more information about CVE-2020-25067 in the NETGEAR security advisory at https://kb.netgear.com/000062158/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R8300-PSV-2020-0211.