CVE-2020-35829: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35829?
The severity of CVE-2020-35829 is medium with a CVSS score of 4.8.
Which NETGEAR devices are affected by CVE-2020-35829?
NETGEAR devices including D7800, R7800, R8900, R9000, RAX120, RBK20, RBR20, RBS20, RBK40, RBR40, RBS40, RBK50, RBR50, RBS50, XR500, and XR700 are affected by CVE-2020-35829.
How can I fix the stored XSS vulnerability in NETGEAR devices?
To fix the stored XSS vulnerability in NETGEAR devices, make sure to update the firmware to the specified versions.
Where can I find more information about CVE-2020-35829?
You can find more information about CVE-2020-35829 including the security advisory and mitigation steps on the NETGEAR Knowledge Base.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-35829?
The CWE ID for CVE-2020-35829 is CWE-79.