Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2020-35822 : Vulnerability Insights and Analysis

Learn about CVE-2020-35822 affecting NETGEAR routers. Discover the impact, affected systems, and mitigation steps to secure your devices against this stored XSS vulnerability.

Certain NETGEAR devices are affected by stored XSS, impacting various router models.

Understanding CVE-2020-35822

What is CVE-2020-35822?

Stored XSS vulnerability affecting NETGEAR devices, including D7800, R7500v2, R7800, R8900, R9000, RAX120, XR500, and XR700.

The Impact of CVE-2020-35822

The vulnerability has a CVSS base score of 6.1 (Medium severity) with high confidentiality and integrity impact.

Technical Details of CVE-2020-35822

Vulnerability Description

Stored XSS vulnerability in NETGEAR devices allows attackers to inject malicious scripts into web pages viewed by users.

Affected Systems and Versions

        D7800 before 1.0.1.56
        R7500v2 before 1.0.3.46
        R7800 before 1.0.2.74
        R8900 before 1.0.4.28
        R9000 before 1.0.4.28
        RAX120 before 1.0.0.78
        XR500 before 2.3.2.56
        XR700 before 1.0.1.10

Exploitation Mechanism

        Attack Complexity: Low
        Attack Vector: Adjacent Network
        Privileges Required: High
        User Interaction: None

Mitigation and Prevention

Immediate Steps to Take

        Update affected devices to the latest firmware versions.
        Disable remote management if not needed.
        Regularly monitor for unusual activities on the network.

Long-Term Security Practices

        Implement strong password policies.
        Conduct regular security audits and penetration testing.
        Educate users about phishing and safe browsing practices.

Patching and Updates

        NETGEAR has released patches to address the vulnerability. Ensure all devices are updated to the patched versions.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now