CVE-2020-35821: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35821?
CVE-2020-35821 is a vulnerability that affects certain NETGEAR devices, allowing for stored cross-site scripting (XSS) attacks.
Which NETGEAR devices are affected by CVE-2020-35821?
CVE-2020-35821 affects the following NETGEAR devices: D7800 (before 1.0.1.56), R7800 (before 1.0.2.74), R8900 (before 1.0.4.28), R9000 (before 1.0.4.28), RAX120 (before 1.0.0.78), RBK20 (before 2.3.5.26), RBR20 (before 2.3.5.26), RBS20 (before 2.3.5.26), RBK40 (before 2.3.5.30), RBR40 (before 2.3.5.30), RBS40 (before 2.3.5.30), RBK50 (before 2.3.5.30), RBR50 (before 2.3.5.30), RBS50 (before 2.3.5.30), XR700 (before 1.0.1.10).
What is the severity of CVE-2020-35821?
The severity of CVE-2020-35821 is medium, with a CVSS score of 4.8.
How does CVE-2020-35821 work?
CVE-2020-35821 allows an attacker to inject malicious scripts into a vulnerable NETGEAR device, which can then be executed by unsuspecting users.
How can I mitigate CVE-2020-35821?
To mitigate CVE-2020-35821, it is recommended to update the firmware of the affected NETGEAR devices to the latest version provided by the manufacturer.