CVE-2020-35800

3 documents3 sources
Severity
9.4CRITICAL
EPSS
1.5%
top 18.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30
Latest updateMay 24

Description

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D6000 before 1.0.0.80, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D7800 before 1.0.3.48, D8500 before 1.0.3.50, DC112A before 1.0.0.48, DGN2200v4 before 1.0.0.114, DM200 before 1.0.0.66, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX2700 before 1.0.1.58

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LExploitability: 3.9 | Impact: 5.5

Affected Packages127 packages

NVDnetgear/r6800_firmware< 1.2.0.72
NVDnetgear/r6900p_firmware< 1.3.2.124
NVDnetgear/r7000p_firmware< 1.3.2.124
NVDnetgear/r7900p_firmware< 1.4.1.62
NVDnetgear/r8000p_firmware< 1.4.1.62

🔴Vulnerability Details

2
GHSA
GHSA-3w6j-54mg-5cr4: Certain NETGEAR devices are affected by incorrect configuration of security settings2022-05-24
CVEList
CVE-2020-35800: Certain NETGEAR devices are affected by incorrect configuration of security settings2020-12-29