PT-2020-12847 · NetGear · R7900+4

Mornaner

·

Published

2020-04-15

·

Updated

2021-07-21

·

CVE-2020-11789

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R6400v2 versions prior to 1.0.4.84 NETGEAR R6700 versions prior to 1.0.2.8 NETGEAR R6700v3 versions prior to 1.0.4.84 NETGEAR R6900 versions prior to 1.0.2.8 NETGEAR R7900 versions prior to 1.0.3.10
Description The issue allows command injection by an unauthenticated attacker.
Recommendations For R6400v2 versions prior to 1.0.4.84, update to version 1.0.4.84 or later. For R6700 versions prior to 1.0.2.8, update to version 1.0.2.8 or later. For R6700v3 versions prior to 1.0.4.84, update to version 1.0.4.84 or later. For R6900 versions prior to 1.0.2.8, update to version 1.0.2.8 or later. For R7900 versions prior to 1.0.3.10, update to version 1.0.3.10 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11789

Affected Products

R6400V2
R6700
R6700V3
R6900
R7900