PT-2020-10707 · NetGear · Ex3700+33

Aircut

·

Published

2020-04-16

·

Updated

2020-08-24

·

CVE-2019-20732

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D6220 versions 1.0.0.0 through 1.0.0.39 D7000v2 versions 1.0.0.0 through 1.0.0.73 D8500 versions 1.0.0.0 through 1.0.3.38 DGN2200v4 versions 1.0.0.0 through 1.0.0.101 DGND2200Bv4 versions 1.0.0.0 through 1.0.0.101 EX3700 versions 1.0.0.0 through 1.0.0.69 EX3800 versions 1.0.0.0 through 1.0.0.69 EX6000 versions 1.0.0.0 through 1.0.0.29 EX6100 versions 1.0.0.0 through 1.0.2.21 EX6120 versions 1.0.0.0 through 1.0.0.39 EX6130 versions 1.0.0.0 through 1.0.0.21 EX6150v1 versions 1.0.0.0 through 1.0.0.41 EX6200 versions 1.0.0.0 through 1.0.3.87 EX7000 versions 1.0.0.0 through 1.0.0.65 R6250 versions 1.0.0.0 through 1.0.4.19 R6300v2 versions 1.0.0.0 through 1.0.4.23 R6400 versions 1.0.0.0 through 1.0.1.31 R6400v2 versions 1.0.0.0 through 1.0.2.43 R6700 versions 1.0.0.0 through 1.0.1.45 R6900 versions 1.0.0.0 through 1.0.1.45 R7000 versions 1.0.0.0 through 1.0.9.25 R6900P versions 1.0.0.0 through 1.3.0.19 R7000P versions 1.0.0.0 through 1.3.0.19 R7100LG versions 1.0.0.0 through 1.0.0.39 R7300DST versions 1.0.0.0 through 1.0.0.61 R7900 versions 1.0.0.0 through 1.0.2.9 R8000 versions 1.0.0.0 through 1.0.4.11 R7900P versions 1.0.0.0 through 1.3.0.9 R8000P versions 1.0.0.0 through 1.3.0.9 R8300 versions 1.0.0.0 through 1.0.2.105 R8500 versions 1.0.0.0 through 1.0.2.105 WN2500RPv2 versions 1.0.0.0 through 1.0.1.53 WNDR3400v3 versions 1.0.0.0 through 1.0.1.17 WNR3500Lv2 versions 1.0.0.0 through 1.2.0.47
Description Certain NETGEAR devices are affected by command injection by an authenticated user.
Recommendations Update D6220 to version 1.0.0.40 or later. Update D7000v2 to version 1.0.0.74 or later. Update D8500 to version 1.0.3.39 or later. Update DGN2200v4 to version 1.0.0.102 or later. Update DGND2200Bv4 to version 1.0.0.102 or later. Update EX3700 to version 1.0.0.70 or later. Update EX3800 to version 1.0.0.70 or later. Update EX6000 to version 1.0.0.30 or later. Update EX6100 to version 1.0.2.22 or later. Update EX6120 to version 1.0.0.40 or later. Update EX6130 to version 1.0.0.22 or later. Update EX6150v1 to version 1.0.0.42 or later. Update EX6200 to version 1.0.3.88 or later. Update EX7000 to version 1.0.0.66 or later. Update R6250 to version 1.0.4.20 or later. Update R6300v2 to version 1.0.4.24 or later. Update R6400 to version 1.0.1.32 or later. Update R6400v2 to version 1.0.2.44 or later. Update R6700 to version 1.0.1.46 or later. Update R6900 to version 1.0.1.46 or later. Update R7000 to version 1.0.9.26 or later. Update R6900P to version 1.3.0.20 or later. Update R7000P to version 1.3.0.20 or later. Update R7100LG to version 1.0.0.40 or later. Update R7300DST to version 1.0.0.62 or later. Update R7900 to version 1.0.2.10 or later. Update R8000 to version 1.0.4.12 or later. Update R7900P to version 1.3.0.10 or later. Update R8000P to version 1.3.0.10 or later. Update R8300 to version 1.0.2.106 or later. Update R8500 to version 1.0.2.106 or later. Update WN2500RPv2 to version 1.0.1.54 or later. Update WNDR3400v3 to version 1.0.1.18 or later. Update WNR3500Lv2 to version 1.2.0.48 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20732

Affected Products

D6220
D7000V2
D8500
Dgn2200V4
Dgnd2200Bv4
Ex3700
Ex3800
Ex6000
Ex6100
Ex6120
Ex6130
Ex6150V1
Ex6200
Ex7000
R6250
R6300V2
R6400
R6400V2
R6700
R6900
R6900P
R7000
R7000P
R7100Lg
R7300Dst
R7900
R7900P
R8000
R8000P
R8300
R8500
Wn2500Rpv2
Wndr3400V3
Wnr3500Lv2