CVE-2019-20749
published 2020-04-16CVE-2019-20749: Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.47, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, R7500v2 before…
PriorityP419medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.52%
41.2th percentile
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.47, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN2000RPTv3 before 1.0.1.32, WN3000RPv3 before 1.0.2.70, and WN3100RPv2 before 1.0.0.66.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | d7800_firmware | < 1.0.1.47 | 1.0.1.47 |
| netgear | ex6100_firmware | < 1.0.1.76 | 1.0.1.76 |
| netgear | ex6150_firmware | < 1.0.1.76 | 1.0.1.76 |
| netgear | r7500_firmware | < 1.0.3.38 | 1.0.3.38 |
| netgear | r7800_firmware | < 1.0.2.52 | 1.0.2.52 |
| netgear | r8900_firmware | < 1.0.4.12 | 1.0.4.12 |
| netgear | r9000_firmware | < 1.0.4.12 | 1.0.4.12 |
| netgear | wn2000rpt_firmware | < 1.0.1.32 | 1.0.1.32 |
| netgear | wn3000rp_firmware | < 1.0.2.70 | 1.0.2.70 |
| netgear | wn3100rp_firmware | < 1.0.0.66 | 1.0.0.66 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv3.04.8MEDIUMCVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65fw-j36g-4qvw: Certain NETGEAR devices are affected by stored XSS
ghsa_unreviewed·2022-05-24
CVE-2019-20749 [LOW] GHSA-65fw-j36g-4qvw: Certain NETGEAR devices are affected by stored XSS
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.47, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN2000RPTv3 before 1.0.1.32, WN3000RPv3 before 1.0.2.70, and WN3100RPv2 before 1.0.0.66.
OSV
italc vulnerabilities
osv·2020-09-28·CVSS 9.8
CVE-2019-15681 italc vulnerabilities
italc vulnerabilities
It was discovered that an information disclosure vulnerability existed in the
LibVNCServer vendored in iTALC when sending a ServerCutText message. An
attacker could possibly use this issue to expose sensitive information.
(CVE-2019-15681)
It was discovered that the LibVNCServer and LibVNCClient vendored in iTALC
incorrectly handled certain packet lengths. A remote attacker could possibly
use this issue to obtain sensitive information, cause a denial of service, or
execute arbitrary code.
(CVE-2018-15127 CVE-2018-20019, CVE-2018-20020, CVE-2018-20021, CVE-2018-20022,
CVE-2018-20023, CVE-2018-20024, CVE-2018-20748, CVE-2018-20749, CVE-2018-20750,
CVE-2018-7225, CVE-2019-15681)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-16
Published