CVE-2020-35789: Input Validation
Published Dec 29, 2020
·Updated
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
Affected Software
2 affected components
Netgear Nms300 Firmware<1.6.0.27
Netgear NMS300
Event History
Dec 29, 2020
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2020-35789?
CVE-2020-35789 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-35789?
To fix CVE-2020-35789, upgrade your NETGEAR NMS300 device firmware to version 1.6.0.27 or later.
3
Who is affected by CVE-2020-35789?
CVE-2020-35789 affects NETGEAR NMS300 devices running firmware versions prior to 1.6.0.27.
4
What type of vulnerability is CVE-2020-35789?
CVE-2020-35789 is a command injection vulnerability that can be exploited by authenticated users.
5
What can happen if CVE-2020-35789 is exploited?
If exploited, CVE-2020-35789 could allow an authenticated attacker to execute arbitrary commands on the affected NETGEAR NMS300 devices.