CVE-2020-11550 allows unauthorized access to sensitive Wi-Fi data on NETGEAR Orbi devices. Learn about the impact, affected systems, and mitigation steps.
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote leak of sensitive/arbitrary Wi-Fi information, such as SSIDs and Pre-Shared-Keys (PSK).
Understanding CVE-2020-11550
This CVE involves a vulnerability in NETGEAR Orbi devices that could lead to unauthorized access to sensitive Wi-Fi information.
What is CVE-2020-11550?
The CVE-2020-11550 vulnerability allows unauthenticated remote attackers to access and leak critical Wi-Fi data from affected NETGEAR Orbi devices.
The Impact of CVE-2020-11550
The vulnerability has a high severity level with a CVSS base score of 7.4, posing a significant risk to confidentiality.
Technical Details of CVE-2020-11550
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The administrative SOAP interface of the affected devices permits unauthorized users to extract sensitive Wi-Fi details like SSIDs and Pre-Shared-Keys.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2020-11550 requires immediate actions and long-term security measures.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates