PT-2020-5881 · NetGear · R6800+13

Published

2020-09-17

·

Updated

2020-10-16

·

CVE-2020-26916

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: NETGEAR D6200 versions before 1.1.00.38 NETGEAR D7000 versions before 1.0.1.78 NETGEAR JR6150 versions before 1.0.1.24 NETGEAR R6020 versions before 1.0.0.42 NETGEAR R6050 versions before 1.0.1.24 NETGEAR R6080 versions before 1.0.0.42 NETGEAR R6120 versions before 1.0.0.66 NETGEAR R6220 versions before 1.1.0.100 NETGEAR R6260 versions before 1.1.0.64 NETGEAR R6700v2 versions before 1.2.0.62 NETGEAR R6800 versions before 1.2.0.62 NETGEAR R6900v2 versions before 1.2.0.62 NETGEAR R7450 versions before 1.2.0.50 NETGEAR WNR2020 versions before 1.1.0.62
Description: The issue is related to the incorrect configuration of security settings in certain NETGEAR devices, which may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. This is due to a lack of protection for service data.
Recommendations: For NETGEAR D6200 version before 1.1.00.38, update to version 1.1.00.38 or later. For NETGEAR D7000 version before 1.0.1.78, update to version 1.0.1.78 or later. For NETGEAR JR6150 version before 1.0.1.24, update to version 1.0.1.24 or later. For NETGEAR R6020 version before 1.0.0.42, update to version 1.0.0.42 or later. For NETGEAR R6050 version before 1.0.1.24, update to version 1.0.1.24 or later. For NETGEAR R6080 version before 1.0.0.42, update to version 1.0.0.42 or later. For NETGEAR R6120 version before 1.0.0.66, update to version 1.0.0.66 or later. For NETGEAR R6220 version before 1.1.0.100, update to version 1.1.0.100 or later. For NETGEAR R6260 version before 1.1.0.64, update to version 1.1.0.64 or later. For NETGEAR R6700v2 version before 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR R6800 version before 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR R6900v2 version before 1.2.0.62, update to version 1.2.0.62 or later. For NETGEAR R7450 version before 1.2.0.50, update to version 1.2.0.50 or later. For NETGEAR WNR2020 version before 1.1.0.62, update to version 1.1.0.62 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01970
CVE-2020-26916

Affected Products

D6200
D7000
Jr6150
R6020
R6050
R6080
R6120
R6220
R6260
R6700V2
R6800
R6900V2
R7450
Wnr2020