PT-2020-10699 · NetGear · Xr500+20

Aircut

·

Published

2020-04-16

·

Updated

2020-08-24

·

CVE-2019-20724

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D3600 versions 1.0.0.0 through 1.0.0.74 D6000 versions 1.0.0.0 through 1.0.0.74 D6100 versions 1.0.0.0 through 1.0.0.62 D7800 versions 1.0.0.0 through 1.0.1.43 R7500v2 versions 1.0.0.0 through 1.0.3.37 R7800 versions 1.0.0.0 through 1.0.2.51 R8900 versions 1.0.0.0 through 1.0.4.1 R9000 versions 1.0.0.0 through 1.0.4.1 RBK20 versions 2.3.0.0 through 2.3.0.27 RBR20 versions 2.3.0.0 through 2.3.0.27 RBS20 versions 2.3.0.0 through 2.3.0.27 RBK50 versions 2.3.0.0 through 2.3.0.31 RBR50 versions 2.3.0.0 through 2.3.0.31 RBS50 versions 2.3.0.0 through 2.3.0.31 RBS40 versions 2.3.0.0 through 2.3.0.27 WNDR3700v4 versions 1.0.0.0 through 1.0.2.101 WNDR4300v1 versions 1.0.0.0 through 1.0.2.103 WNDR4300v2 versions 1.0.0.0 through 1.0.0.57 WNDR4500v3 versions 1.0.0.0 through 1.0.0.57 WNR2000v5 versions 1.0.0.0 through 1.0.0.67 XR500 versions 2.3.2.0 through 2.3.2.31
Description Certain NETGEAR devices are affected by command injection by an authenticated user.
Recommendations D3600 versions 1.0.0.0 through 1.0.0.74: Update to version 1.0.0.75 or later. D6000 versions 1.0.0.0 through 1.0.0.74: Update to version 1.0.0.75 or later. D6100 versions 1.0.0.0 through 1.0.0.62: Update to version 1.0.0.63 or later. D7800 versions 1.0.0.0 through 1.0.1.43: Update to version 1.0.1.44 or later. R7500v2 versions 1.0.0.0 through 1.0.3.37: Update to version 1.0.3.38 or later. R7800 versions 1.0.0.0 through 1.0.2.51: Update to version 1.0.2.52 or later. R8900 versions 1.0.0.0 through 1.0.4.1: Update to version 1.0.4.2 or later. R9000 versions 1.0.0.0 through 1.0.4.1: Update to version 1.0.4.2 or later. RBK20 versions 2.3.0.0 through 2.3.0.27: Update to version 2.3.0.28 or later. RBR20 versions 2.3.0.0 through 2.3.0.27: Update to version 2.3.0.28 or later. RBS20 versions 2.3.0.0 through 2.3.0.27: Update to version 2.3.0.28 or later. RBK50 versions 2.3.0.0 through 2.3.0.31: Update to version 2.3.0.32 or later. RBR50 versions 2.3.0.0 through 2.3.0.31: Update to version 2.3.0.32 or later. RBS50 versions 2.3.0.0 through 2.3.0.31: Update to version 2.3.0.32 or later. RBS40 versions 2.3.0.0 through 2.3.0.27: Update to version 2.3.0.28 or later. WNDR3700v4 versions 1.0.0.0 through 1.0.2.101: Update to version 1.0.2.102 or later. WNDR4300v1 versions 1.0.0.0 through 1.0.2.103: Update to version 1.0.2.104 or later. WNDR4300v2 versions 1.0.0.0 through 1.0.0.57: Update to version 1.0.0.58 or later. WNDR4500v3 versions 1.0.0.0 through 1.0.0.57: Update to version 1.0.0.58 or later. WNR2000v5 versions 1.0.0.0 through 1.0.0.67: Update to version 1.0.0.68 or later. XR500 versions 2.3.2.0 through 2.3.2.31: Update to version 2.3.2.32 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20724

Affected Products

D3600
D6000
D6100
D7800
R7500V2
R7800
R8900
R9000
Rbk20
Rbk50
Rbr20
Rbr50
Rbs20
Rbs40
Rbs50
Wndr3700V4
Wndr4300V1
Wndr4300V2
Wndr4500V3
Wnr2000V5
Xr500