PT-2020-8332 · NetGear · Jnr1010V2+17
Published
2020-04-22
·
Updated
2020-04-24
·
CVE-2017-18783
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
D6200 versions 1.1.00.24 and earlier
D7000 versions 1.0.1.52 and earlier
JNR1010v2 versions 1.1.0.44 and earlier
JR6150 versions 1.0.1.12 and earlier
JWNR2010v5 versions 1.1.0.44 and earlier
PR2000 versions 1.0.0.20 and earlier
R6020 versions 1.0.0.26 and earlier
R6050 versions 1.0.1.12 and earlier
R6080 versions 1.0.0.26 and earlier
R6120 versions 1.0.0.36 and earlier
R6220 versions 1.1.0.60 and earlier
R6700v2 versions 1.2.0.12 and earlier
R6800 versions 1.2.0.12 and earlier
R6900v2 versions 1.2.0.12 and earlier
WNDR3700v5 versions 1.1.0.50 and earlier
WNR1000v4 versions 1.1.0.44 and earlier
WNR2020 versions 1.1.0.44 and earlier
WNR2050 versions 1.1.0.44 and earlier
Description:
Certain NETGEAR devices are affected by a cross-site scripting (XSS) issue. This allows attackers to inject malicious scripts into the device's web interface.
Recommendations:
For D6200 version 1.1.00.24 and earlier, update to version 1.1.00.24 or later.
For D7000 version 1.0.1.52 and earlier, update to version 1.0.1.52 or later.
For JNR1010v2 version 1.1.0.44 and earlier, update to version 1.1.0.44 or later.
For JR6150 version 1.0.1.12 and earlier, update to version 1.0.1.12 or later.
For JWNR2010v5 version 1.1.0.44 and earlier, update to version 1.1.0.44 or later.
For PR2000 version 1.0.0.20 and earlier, update to version 1.0.0.20 or later.
For R6020 version 1.0.0.26 and earlier, update to version 1.0.0.26 or later.
For R6050 version 1.0.1.12 and earlier, update to version 1.0.1.12 or later.
For R6080 version 1.0.0.26 and earlier, update to version 1.0.0.26 or later.
For R6120 version 1.0.0.36 and earlier, update to version 1.0.0.36 or later.
For R6220 version 1.1.0.60 and earlier, update to version 1.1.0.60 or later.
For R6700v2 version 1.2.0.12 and earlier, update to version 1.2.0.12 or later.
For R6800 version 1.2.0.12 and earlier, update to version 1.2.0.12 or later.
For R6900v2 version 1.2.0.12 and earlier, update to version 1.2.0.12 or later.
For WNDR3700v5 version 1.1.0.50 and earlier, update to version 1.1.0.50 or later.
For WNR1000v4 version 1.1.0.44 and earlier, update to version 1.1.0.44 or later.
For WNR2020 version 1.1.0.44 and earlier, update to version 1.1.0.44 or later.
For WNR2050 version 1.1.0.44 and earlier, update to version 1.1.0.44 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D6200
D7000
Jnr1010V2
Jr6150
Jwnr2010V5
Pr2000
R6020
R6050
R6080
R6120
R6220
R6700V2
R6800
R6900V2
Wndr3700V5
Wnr1000V4
Wnr2020
Wnr2050