First published: Tue Sep 01 2020(Updated: )
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R8300 Firmware | <1.0.2.134 | |
NETGEAR R8300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25067 is a vulnerability in NETGEAR R8300 devices before 1.0.2.134 that allows an unauthenticated attacker to perform command injection.
CVE-2020-25067 affects NETGEAR R8300 devices before 1.0.2.134 by allowing an unauthenticated attacker to execute arbitrary commands.
CVE-2020-25067 has a severity rating of 8.8 (critical).
To fix CVE-2020-25067 on your NETGEAR R8300 device, update the firmware to version 1.0.2.134 or later.
You can find more information about CVE-2020-25067 in the NETGEAR security advisory at https://kb.netgear.com/000062158/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R8300-PSV-2020-0211.