MEDIUM · 4.8

CVE-2019-20661

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

Vulnerability Description

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
NetgearRbr50 Firmware< 2.3.5.30
NetgearRbr50-
NetgearRbk50 Firmware< 2.3.5.30
NetgearRbk50-
NetgearRbs50 Firmware< 2.3.5.30
NetgearRbs50-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-20661?

CVE-2019-20661 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

How severe is CVE-2019-20661?

CVE-2019-20661 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-20661?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Rbr50 Firmware, Netgear Rbr50, Netgear Rbk50 Firmware, Netgear Rbk50, Netgear Rbs50 Firmware.