CVE-2020-26918

Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before 1.0.2.128.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex7000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:r6250_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6250:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6700v3:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:r7100lg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7100lg:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:r7300dst_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7300dst:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:r7900_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7900:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:r8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8300:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:r8500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:20

Type Values Removed Values Added
CVSS v2 : 3.5
v3 : 4.8
v2 : 3.5
v3 : 4.1
References () https://kb.netgear.com/000062335/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Extenders-and-Routers-PSV-2018-0243 - Vendor Advisory () https://kb.netgear.com/000062335/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Extenders-and-Routers-PSV-2018-0243 - Vendor Advisory

Information

Published : 2020-10-09 07:15

Updated : 2024-11-21 05:20


NVD link : CVE-2020-26918

Mitre link : CVE-2020-26918

CVE.ORG link : CVE-2020-26918


JSON object : View

Products Affected

netgear

  • r6250_firmware
  • r6700v3
  • r8500
  • ex7000_firmware
  • r6400v2
  • r7300dst_firmware
  • r7100lg
  • r6700v3_firmware
  • r8300_firmware
  • r8300
  • r8500_firmware
  • r6250
  • ex7000
  • r7100lg_firmware
  • r6400
  • r6400_firmware
  • r6400v2_firmware
  • r7900
  • r7300dst
  • r7900_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')