First published: Fri Oct 09 2020(Updated: )
Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before 1.0.2.128.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Ex7000 Firmware | <1.0.1.78 | |
NETGEAR EX7000 | ||
netgear R6250 Firmware | <1.0.4.34 | |
NETGEAR R6250 | ||
Netgear R6400 Firmware | <1.0.1.46 | |
NETGEAR R6400 | ||
Netgear R6400v2 Firmware | <1.0.2.66 | |
NETGEAR R6400v2 | ||
Netgear R6700v3 Firmware | <1.0.2.66 | |
NETGEAR R6700v3 | ||
Netgear R7100lg Firmware | <1.0.0.50 | |
Netgear R7100LG | ||
Netgear R7300dst Firmware | <1.0.0.70 | |
Netgear R7300dst | ||
Netgear R7900 Firmware | <1.0.3.8 | |
Netgear R7900 | ||
Netgear R8300 Firmware | <1.0.2.128 | |
NETGEAR R8300 | ||
Netgear R8500 Firmware | <1.0.2.128 | |
NETGEAR R8500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The affected NETGEAR devices are EX7000, R6250, R6400, R6400v2, R6700v3, R7100LG, R7300DST, R7900, R8300, and R8500.
The severity of CVE-2020-26918 is medium with a severity value of 4.8.
To fix the stored XSS vulnerability, you should update your NETGEAR device firmware to version 1.0.1.78 for EX7000, 1.0.4.34 for R6250, 1.0.1.46 for R6400, 1.0.2.66 for R6400v2 and R6700v3, 1.0.0.50 for R7100LG, 1.0.0.70 for R7300DST, 1.0.3.8 for R7900, 1.0.2.128 for R8300, and 1.0.2.128 for R8500.
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2020-26918.
Yes, you can find more information about this vulnerability at the following link: [https://kb.netgear.com/000062335/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Extenders-and-Routers-PSV-2018-0243](https://kb.netgear.com/000062335/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Extenders-and-Routers-PSV-2018-0243)