7.8
CVSSv2

CVE-2020-35782

Published: 30/12/2020 Updated: 26/03/2021
CVSS v2 Base Score: 7.8 | Impact Score: 9.2 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 694
Vector: AV:A/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Summary

Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE prior to 2.6.0.48, JGS524Ev2 prior to 2.6.0.48, JGS524PE prior to 2.6.0.48, and GS116Ev2 prior to 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote malicious users to write arbitrary data to internal memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgear jgs516pe_firmware

netgear jgs524e_firmware

netgear jgs524pe_firmware

netgear gs116e_firmware