Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, RAX120 before 1.0.0.78, RBK22 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and WN3000RPv2 before 1.0.0.78.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
History
04 Jan 2021, 15:48
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://kb.netgear.com/000062729/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Routers-and-Orbi-WiFi-Systems-PSV-2018-0539 - Vendor Advisory | |
CPE | cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7500v2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs40_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr40_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbk40:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs50_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs20:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbk50_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbk40_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs40:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr20:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax120:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbk50:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:wn3000rpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbk22_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr50_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs50:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbk22:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr50:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax120_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7500v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr40:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:wn3000rpv2:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 4.8 |
CWE | CWE-79 |
30 Dec 2020, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2020-12-30 00:15
Updated : 2023-12-10 13:41
NVD link : CVE-2020-35806
Mitre link : CVE-2020-35806
CVE.ORG link : CVE-2020-35806
JSON object : View
Products Affected
netgear
- wn3000rpv2_firmware
- rbk40_firmware
- rbr50
- rbs50
- rbk22_firmware
- rbk40
- rbr20_firmware
- rbs20_firmware
- d7800_firmware
- d7800
- rax120
- rbk22
- r7800
- rbr40
- rbr20
- rbr40_firmware
- rbk50
- rax120_firmware
- rbk50_firmware
- r7500v2_firmware
- rbs40_firmware
- wn3000rpv2
- rbs40
- rbs20
- rbs50_firmware
- rbr50_firmware
- r7800_firmware
- r7500v2
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')