CVE-2020-35824: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35824?
CVE-2020-35824 is a vulnerability that affects certain NETGEAR devices and allows for stored cross-site scripting (XSS) attacks.
Which NETGEAR devices are affected by CVE-2020-35824?
The NETGEAR devices affected by CVE-2020-35824 include D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and XR500 before 2.3.2.56.
What is the severity of CVE-2020-35824?
The severity of CVE-2020-35824 is medium with a CVSSv3 score of 4.8.
How does CVE-2020-35824 work?
CVE-2020-35824 allows an attacker to inject malicious scripts into stored data on the affected NETGEAR devices, which can then be executed when accessed by other users.
How can I fix CVE-2020-35824?
To fix CVE-2020-35824, it is recommended to update the firmware of the affected NETGEAR devices to the patched versions provided by NETGEAR.