CVE-2020-35833: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35833?
The severity of CVE-2020-35833 is medium with a severity value of 4.8.
Which NETGEAR devices are affected by CVE-2020-35833?
The NETGEAR devices affected by CVE-2020-35833 are D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, XR700 before 1.0.1.10.
Is the Netgear D7800 vulnerable to CVE-2020-35833?
No, the Netgear D7800 is not vulnerable to CVE-2020-35833.
How do I fix CVE-2020-35833?
To fix CVE-2020-35833, it is recommended to update the firmware of the affected NETGEAR devices to the latest versions provided by NETGEAR.
Where can I find more information about CVE-2020-35833?
More information about CVE-2020-35833 can be found in the NETGEAR Security Advisory for Stored Cross-Site Scripting on Some Routers and WiFi Systems (PSV-2018-0512) at https://kb.netgear.com/000062677/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Routers-and-WiFi-Systems-PSV-2018-0512.