PT-2020-10634 · NetGear · R7900+4
Nstarke
·
Published
2020-04-15
·
Updated
2020-08-24
·
CVE-2019-20659
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR R6400v2 versions prior to 1.0.4.84
NETGEAR R6700 versions prior to 1.0.2.8
NETGEAR R6700v3 versions prior to 1.0.4.84
NETGEAR R6900 versions prior to 1.0.2.8
NETGEAR R7900 versions prior to 1.0.3.10
Description
The issue allows for command injection by an authenticated user.
Recommendations
For R6400v2, update to version 1.0.4.84 or later.
For R6700, update to version 1.0.2.8 or later.
For R6700v3, update to version 1.0.4.84 or later.
For R6900, update to version 1.0.2.8 or later.
For R7900, update to version 1.0.3.10 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
R6400V2
R6700
R6700V3
R6900
R7900