CVE-2020-26914: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26914?
CVE-2020-26914 is a vulnerability that allows command injection by an authenticated user on certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2020-26914?
The following NETGEAR devices are affected by CVE-2020-26914: D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and Wnr2020 before 1.1.0.62.
What is the severity of CVE-2020-26914?
CVE-2020-26914 has a severity rating of 7.1 (high).
How does CVE-2020-26914 work?
CVE-2020-26914 allows an authenticated user to execute arbitrary commands on affected NETGEAR devices, potentially leading to unauthorized access or control of the device.
How can I fix CVE-2020-26914?
To fix CVE-2020-26914, update the firmware of the affected NETGEAR devices to versions above the vulnerable ones mentioned in the advisory.