First published: Tue Dec 29 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48, R8900 before 1.0.5.2, R9000 before 1.0.5.2, and R7800 before 1.0.2.68.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R7500v2 firmware | <1.0.3.48 | |
NETGEAR R7500v2 firmware | =v2 | |
NETGEAR R8900 firmware | <1.0.5.2 | |
NETGEAR R8900 | ||
NETGEAR R9000 firmware | <1.0.5.2 | |
NETGEAR R9000 firmware | ||
NETGEAR R7800 firmware | <1.0.2.68 | |
NETGEAR R7800 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35792 is considered high due to the command injection vulnerability that could allow authenticated users to execute arbitrary commands.
To fix CVE-2020-35792, update your NETGEAR device firmware to the latest version available for your model.
CVE-2020-35792 affects NETGEAR R7500v2 before version 1.0.3.48, R8900 before version 1.0.5.2, R9000 before version 1.0.5.2, and R7800 before version 1.0.2.68.
CVE-2020-35792 is a command injection vulnerability that can be exploited by authenticated users.
Yes, CVE-2020-35792 can compromise your home network security if an attacker gains authenticated access to your vulnerable NETGEAR device.