PT-2020-17438 · NetGear · Netgear R7800+25

Published

2020-12-29

·

Updated

2021-01-04

·

CVE-2020-35798

CVSS v3.1

9.3

Critical

VectorAC:L/AV:L/A:H/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions NETGEAR R6400v2 versions 1.0.4.84 and earlier NETGEAR R6700v3 versions 1.0.4.84 and earlier NETGEAR R6900P versions 1.3.2.124 and earlier NETGEAR R7000 versions 1.0.11.100 and earlier NETGEAR R7000P versions 1.3.2.124 and earlier NETGEAR R7800 versions 1.0.2.74 and earlier NETGEAR R7850 versions 1.0.5.60 and earlier NETGEAR R7900 versions 1.0.4.26 and earlier NETGEAR R7960P versions 1.4.1.50 and earlier NETGEAR R8000 versions 1.0.4.52 and earlier NETGEAR R7900P versions 1.4.1.50 and earlier NETGEAR R8000P versions 1.4.1.50 and earlier NETGEAR RAX15 versions 1.0.1.64 and earlier NETGEAR RAX20 versions 1.0.1.64 and earlier NETGEAR RAX200 versions 1.0.1.12 and earlier NETGEAR RAX45 versions 1.0.2.66 and earlier NETGEAR RAX50 versions 1.0.2.66 and earlier NETGEAR RAX75 versions 1.0.3.102 and earlier NETGEAR RAX80 versions 1.0.3.102 and earlier NETGEAR RBK752 versions 3.2.16.6 and earlier NETGEAR RBR750 versions 3.2.16.6 and earlier NETGEAR RBS750 versions 3.2.16.6 and earlier NETGEAR RBK852 versions 3.2.15.25 and earlier NETGEAR RBR850 versions 3.2.15.25 and earlier NETGEAR RBS850 versions 3.2.15.25 and earlier NETGEAR RBK842 versions 3.2.15.25 and earlier NETGEAR RBR840 versions 3.2.15.25 and earlier NETGEAR RBS840 versions 3.2.15.25 and earlier NETGEAR RS400 versions 1.5.0.48 and earlier NETGEAR XR300 versions 1.0.3.50 and earlier
Description Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
Recommendations Update NETGEAR R6400v2 to version 1.0.4.84 or later Update NETGEAR R6700v3 to version 1.0.4.84 or later Update NETGEAR R6900P to version 1.3.2.124 or later Update NETGEAR R7000 to version 1.0.11.100 or later Update NETGEAR R7000P to version 1.3.2.124 or later Update NETGEAR R7800 to version 1.0.2.74 or later Update NETGEAR R7850 to version 1.0.5.60 or later Update NETGEAR R7900 to version 1.0.4.26 or later Update NETGEAR R7960P to version 1.4.1.50 or later Update NETGEAR R8000 to version 1.0.4.52 or later Update NETGEAR R7900P to version 1.4.1.50 or later Update NETGEAR R8000P to version 1.4.1.50 or later Update NETGEAR RAX15 to version 1.0.1.64 or later Update NETGEAR RAX20 to version 1.0.1.64 or later Update NETGEAR RAX200 to version 1.0.1.12 or later Update NETGEAR RAX45 to version 1.0.2.66 or later Update NETGEAR RAX50 to version 1.0.2.66 or later Update NETGEAR RAX75 to version 1.0.3.102 or later Update NETGEAR RAX80 to version 1.0.3.102 or later Update NETGEAR RBK752 to version 3.2.16.6 or later Update NETGEAR RBR750 to version 3.2.16.6 or later Update NETGEAR RBS750 to version 3.2.16.6 or later Update NETGEAR RBK852 to version 3.2.15.25 or later Update NETGEAR RBR850 to version 3.2.15.25 or later Update NETGEAR RBS850 to version 3.2.15.25 or later Update NETGEAR RBK842 to version 3.2.15.25 or later Update NETGEAR RBR840 to version 3.2.15.25 or later Update NETGEAR RBS840 to version 3.2.15.25 or later Update NETGEAR RS400 to version 1.5.0.48 or later Update NETGEAR XR300 to version 1.0.3.50 or later

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35798

Affected Products

Netgear R6400V2
Netgear R6700V3
Netgear R6900P
Netgear R7000
Netgear R7000P
Netgear R7800
Netgear R7850
Netgear R7900
Netgear R7960P
Netgear R8000
Netgear Rax15
Netgear Rax20
Netgear Rax200
Netgear Rax45
Netgear Rax50
Netgear Rax75
Netgear Rax80
Netgear Rbk752
Netgear Rbk842
Netgear Rbk852
Netgear Rbr750
Netgear Rbs840
Netgear Rbr850
Netgear Rbs750
Netgear Rs400
Netgear Xr300