Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
2020-04-16T19:15:24.133
2024-11-21T04:39:07.460
Modified
CVSSv3.1: 8.0 (HIGH)
AV:A/AC:L/Au:S/C:P/I:P/A:P
5.1
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | xr500_firmware | < 2.3.2.32 | Yes |
Hardware | netgear | xr500 | - | No |
Operating System | netgear | d3600_firmware | < 1.0.0.76 | Yes |
Hardware | netgear | d3600 | - | No |
Operating System | netgear | d6000_firmware | < 1.0.0.76 | Yes |
Hardware | netgear | d6000 | - | No |