First published: Fri Oct 09 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110, and SRS60 before 2.5.3.110.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR SRK60 | <2.5.3.110 | |
NETGEAR SRK60 firmware | ||
NETGEAR SRR60 Firmware | <2.5.3.110 | |
NETGEAR SRR60 Firmware | ||
NETGEAR SRS60 firmware | <2.5.3.110 | |
NETGEAR SRS60 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26920 is classified as a high severity vulnerability due to the potential for unauthorized command execution.
To mitigate CVE-2020-26920, update affected devices to firmware version 2.5.3.110 or later.
CVE-2020-26920 affects NETGEAR SRK60, SRR60, and SRS60 devices running firmware versions prior to 2.5.3.110.
Yes, CVE-2020-26920 can be exploited by an unauthenticated attacker.
CVE-2020-26920 is a command injection vulnerability.