CVE-2020-26915: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-26915.
What is the severity rating of CVE-2020-26915?
The severity rating of CVE-2020-26915 is 4.8 (medium).
Which NETGEAR devices are affected by CVE-2020-26915?
NETGEAR devices D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56 are affected by CVE-2020-26915.
What is the workaround for CVE-2020-26915?
There is no known workaround for CVE-2020-26915 at the moment.
Where can I find more information about CVE-2020-26915?
You can find more information about CVE-2020-26915 at the following link: [Netgear Security Advisory](https://kb.netgear.com/000062338/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Routers-and-WiFi-Systems-PSV-2018-0554).