CVE-2020-35223: CSRF
The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-35223.
What is the severity of CVE-2020-35223?
The severity of CVE-2020-35223 is high with a CVSS score of 8.8.
Which devices are affected by CVE-2020-35223?
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices are affected by CVE-2020-35223.
How can the CSRF protection mechanism be bypassed?
The CSRF protection mechanism can be bypassed by omitting the CSRF token parameter in HTTP requests.
Where can I find more information about CVE-2020-35223?
More information about CVE-2020-35223 can be found at the following reference link: [https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/](https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/)