CVE-2020-35794: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS40V before 2.6.1.4, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35794?
CVE-2020-35794 is a vulnerability that affects certain NETGEAR devices and allows a authenticated user to execute arbitrary commands.
Which devices are affected by CVE-2020-35794?
The following NETGEAR devices are affected by CVE-2020-35794: RBS40V before version 2.6.1.4, RBK752 before version 3.2.15.25, RBR750 before version 3.2.15.25, RBS750 before version 3.2.15.25, RBK852 before version 3.2.15.25, RBR850 before version 3.2.15.25, and RBS850 before version 3.2.15.25.
What is the severity of CVE-2020-35794?
The severity of CVE-2020-35794 is high with a CVSS score of 6.8.
How can an authenticated user exploit CVE-2020-35794?
An authenticated user can exploit CVE-2020-35794 by injecting and executing arbitrary commands on the affected NETGEAR devices.
How can I fix CVE-2020-35794?
To fix CVE-2020-35794, users should update their NETGEAR devices to the patched firmware versions mentioned in the Netgear Security Advisory.