CVE-2020-26909: Command Injection
Published Oct 9, 2020
·Updated
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3.48.
Affected Software
4 affected components
Netgear D7800 Firmware<1.0.1.58
Netgear D7800
Netgear R7500v2 Firmware<1.0.3.48
Netgear R7500v2
Event History
Oct 9, 2020
CVE Published
via MITRE·06:31 AM
Data Sourced
via MITRE·06:31 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2020-26909?
The severity of CVE-2020-26909 is high with a severity value of 8.8.
2
Which NETGEAR devices are affected by CVE-2020-26909?
The NETGEAR D7800 before 1.0.1.58 and R7500v2 before 1.0.3.48 are affected by CVE-2020-26909.
3
Is authentication required to exploit CVE-2020-26909?
No, CVE-2020-26909 can be exploited by an unauthenticated attacker.
4
How can I fix CVE-2020-26909?
To fix CVE-2020-26909, update your NETGEAR D7800 firmware to version 1.0.1.58 or later, and update your NETGEAR R7500v2 firmware to version 1.0.3.48 or later.
5
Where can I find more information about CVE-2020-26909?
You can find more information about CVE-2020-26909 on the Netgear security advisory page.