First published: Tue Dec 29 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.5.2, and R9000 before 1.0.5.2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear D7800 Firmware | <1.0.1.58 | |
Netgear D7800 | ||
Netgear R7500 Firmware | <1.0.3.46 | |
Netgear R7500 | =v2 | |
NETGEAR R7800 firmware | <1.0.2.74 | |
NETGEAR R7800 | ||
Netgear R8900 Firmware | <1.0.5.2 | |
NETGEAR R8900 | ||
Netgear R9000 Firmware | <1.0.5.2 | |
NETGEAR R9000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35793 is a vulnerability affecting certain NETGEAR devices, allowing command injection by an authenticated user.
NETGEAR devices D7800, R7500v2, R7800, R8900, and R9000 are affected by CVE-2020-35793.
CVE-2020-35793 has a severity rating of 6.7, which is considered medium severity.
An authenticated user can exploit CVE-2020-35793 by injecting commands into the affected NETGEAR devices.
Yes, NETGEAR has released firmware updates to fix the CVE-2020-35793 vulnerability. Please refer to the official NETGEAR security advisory for more information.