PT-2020-6288 · NetGear · Netgear Dgn2200V1

Published

2020-12-15

·

Updated

2024-03-05

·

CVE-2020-35785

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR DGN2200v1 devices version 1.0.0.59 and earlier
Description The issue is related to the mishandling of HTTPd authentication in the NETGEAR DGN2200v1 devices, which can be exploited by a remote attacker to execute arbitrary code. This is due to deficiencies in the authentication procedure of the HTTPd daemon in the router's firmware.
Recommendations For NETGEAR DGN2200v1 devices version 1.0.0.59 and earlier, update to version 1.0.0.60 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTPd daemon to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-03933
CVE-2020-35785

Affected Products

Netgear Dgn2200V1