PT-2020-13392 · NetGear · Netgear R7800+15

Dieter Vymazal

+4

·

Published

2020-05-28

·

Updated

2020-05-29

·

CVE-2020-13245

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NETGEAR R7000 versions 1.0.9.6 1.2.19 through 1.0.11.100 10.2.10 NETGEAR R6120 (affected versions not specified) NETGEAR R7800 (affected versions not specified) NETGEAR R6220 (affected versions not specified) NETGEAR R8000 (affected versions not specified) NETGEAR R6350 (affected versions not specified) NETGEAR R9000 (affected versions not specified) NETGEAR R6400 (affected versions not specified) NETGEAR RAX120 (affected versions not specified) NETGEAR R6400v2 (affected versions not specified) NETGEAR RBR20 (affected versions not specified) NETGEAR R6800 (affected versions not specified) NETGEAR XR300 (affected versions not specified) NETGEAR R6850 (affected versions not specified) NETGEAR XR500 (affected versions not specified) NETGEAR R7000P (affected versions not specified)
Description The issue is related to Missing SSL Certificate Validation, which affects certain NETGEAR devices.
Recommendations For NETGEAR R7000 versions 1.0.9.6 1.2.19 through 1.0.11.100 10.2.10, update to a version outside of this range to resolve the issue. For NETGEAR R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13245

Affected Products

Netgear R6120
Netgear R6220
Netgear R6350
Netgear R6400
Netgear R6400V2
Netgear R6800
Netgear R6850
Netgear R7000
Netgear R7000P
Netgear R7800
Netgear R8000
Netgear R9000
Netgear Rax120
Netgear Rbr20
Netgear Xr300
Netgear Xr500