CVE-2020-35816: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the stored XSS vulnerability on certain NETGEAR devices?
The vulnerability ID for the stored XSS vulnerability on certain NETGEAR devices is CVE-2020-35816.
Which NETGEAR devices are affected by the stored XSS vulnerability?
The following NETGEAR devices are affected by the stored XSS vulnerability: D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30.
What is the severity of CVE-2020-35816?
The severity of CVE-2020-35816 is medium, with a severity value of 4.8.
How can I fix the stored XSS vulnerability on my NETGEAR device?
To fix the stored XSS vulnerability on your NETGEAR device, update the firmware to the latest version provided by NETGEAR.
Where can I find more information about the stored XSS vulnerability on NETGEAR devices?
You can find more information about the stored XSS vulnerability on NETGEAR devices in the NETGEAR Security Advisory for Stored Cross-Site Scripting (PSV-2018-0492).