CVE-2020-35798: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900 before 1.0.4.26, R7960P before 1.4.1.50, R8000 before 1.0.4.52, R7900P before 1.4.1.50, R8000P before 1.4.1.50, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX200 before 1.0.1.12, RAX45 before 1.0.2.66, RAX50 before 1.0.2.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, RBS850 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RS400 before 1.5.0.48, and XR300 before 1.0.3.50.
Affected Software
Event History
Frequently Asked Questions
Which devices are affected by CVE-2020-35798?
NETGEAR R6400v2, R6700v3, R6900P, R7000, R7000P, R7800, R7850, R7900, R7960p, R8000, R8000p, Rax15, Rax20, Rax200, Rax45, Rax50, Rax75, Rax80, Rbk752, Rbr750, Rbs750, Rbk852, Rbr850, Rbs850, Rbk842, Rbr840, Rbs840, Rs400, XR300.
What is the severity level of CVE-2020-35798?
The severity level of CVE-2020-35798 is critical.
How does CVE-2020-35798 impact NETGEAR devices?
CVE-2020-35798 allows an unauthenticated attacker to execute arbitrary commands on affected NETGEAR devices.
Is my device vulnerable to CVE-2020-35798?
If you have one of the affected NETGEAR devices mentioned in the advisory, your device could be vulnerable to CVE-2020-35798.
How can I mitigate the vulnerability in my NETGEAR device?
To mitigate the vulnerability, update your device's firmware to the latest version provided by NETGEAR.