CVE-2020-35815: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBK40 before 2.3.5.30, RBK40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What devices are affected by the stored XSS vulnerability (CVE-2020-35815)?
The vulnerability affects certain NETGEAR devices including D7800, R7500v2, R7800, R8900, R9000, RAX120, RBK20, RBR20, RBS20, RBK40, RBK50, RBR50, RBS50, XR500, and XR700.
What is the severity of the stored XSS vulnerability (CVE-2020-35815)?
The severity of the vulnerability is medium with a CVSS score of 4.8.
How can I check if my NETGEAR device is vulnerable to CVE-2020-35815?
You can check if your device is vulnerable by referring to the NETGEAR security advisory or contacting NETGEAR support.
How do I fix the stored XSS vulnerability on my NETGEAR device?
To fix the vulnerability, you need to update your NETGEAR device firmware to the recommended version provided by NETGEAR. Refer to the NETGEAR security advisory for specific instructions.
What is the Common Weakness Enumeration (CWE) ID for the stored XSS vulnerability (CVE-2020-35815)?
The CWE ID for the vulnerability is CWE-79.