PT-2020-5872 · NetGear · Ac2400+16

Published

2020-09-17

·

Updated

2021-07-21

·

CVE-2020-26927

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NETGEAR D6200 versions prior to 1.1.00.40 NETGEAR D7000 versions prior to 1.0.1.78 NETGEAR R6020 versions prior to 1.0.0.42 NETGEAR R6080 versions prior to 1.0.0.42 NETGEAR R6050 versions prior to 1.0.1.26 NETGEAR JR6150 versions prior to 1.0.1.26 NETGEAR R6120 versions prior to 1.0.0.66 NETGEAR R6220 versions prior to 1.1.0.100 NETGEAR R6260 versions prior to 1.1.0.66 NETGEAR R6700v2 versions prior to 1.2.0.62 NETGEAR R6800 versions prior to 1.2.0.62 NETGEAR R6900v2 versions prior to 1.2.0.62 NETGEAR AC2100 versions prior to 1.2.0.62 NETGEAR AC2400 versions prior to 1.2.0.62 NETGEAR AC2600 versions prior to 1.2.0.62 NETGEAR R7450 versions prior to 1.2.0.62 NETGEAR WNR2020 versions prior to 1.1.0.62
Description: The issue is related to authentication bypass in certain NETGEAR devices. This can be exploited by a remote attacker to cause a denial of service. The vulnerability is associated with deficiencies in the authentication mechanism of the affected Wi-Fi routers.
Recommendations: For NETGEAR D6200 versions prior to 1.1.00.40, update to version 1.1.00.40 or later. For NETGEAR D7000 versions prior to 1.0.1.78, update to version 1.0.1.78 or later. For NETGEAR R6020 versions prior to 1.0.0.42, update to version 1.0.0.42 or later. For NETGEAR R6080 versions prior to 1.0.0.42, update to version 1.0.0.42 or later. For NETGEAR R6050 versions prior to 1.0.1.26, update to version 1.0.1.26 or later. For NETGEAR JR6150 versions prior to 1.0.1.26, update to version 1.0.1.26 or later. For NETGEAR R6120 versions prior to 1.0.0.66, update to version 1.0.0.66 or later. For NETGEAR R6220 versions prior to 1.1.0.100, update to version 1.1.0.100 or later. For NETGEAR R6260 versions prior to 1.1.0.66, update to version 1.1.0.66 or later. For NETGEAR R6700v2 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR R6800 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR R6900v2 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR AC2100 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR AC2400 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR AC2600 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR R7450 versions prior to 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR WNR2020 versions prior to 1.1.0.62, update to version 1.1.0.62 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01926
CVE-2020-26927

Affected Products

Ac2100
Ac2400
Ac2600
D6200
D7000
Jr6150
R6020
R6050
R6080
R6120
R6220
R6260
R6700V2
R6800
R6900V2
R7450
Wnr2020