Severity
8.8HIGH
EPSS
0.8%
top 25.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Latest updateMay 24

Description

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDnetgear/nms300_firmware< 1.6.0.27

🔴Vulnerability Details

2
GHSA
GHSA-3wm3-m3jr-6jpv: NETGEAR NMS300 devices before 12022-05-24
CVEList
CVE-2020-35789: NETGEAR NMS300 devices before 12020-12-29
CVE-2020-35789 (HIGH CVSS 8.8) | NETGEAR NMS300 devices before 1.6.0 | cvebase.io