5.5
CVSSv2

CVE-2020-35801

Published: 30/12/2020 Updated: 23/03/2021
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.3 | Impact Score: 5.2 | Exploitability Score: 2.1
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE prior to 2.6.0.48, JGS524Ev2 prior to 2.6.0.48, JGS524PE prior to 2.6.0.48, and GS116Ev2 prior to 2.6.0.48. A TFTP server was found to be active by default. It allows remote authenticated users to update the switch firmware.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgear jgs516pe_firmware

netgear jgs524e_firmware

netgear jgs524pe_firmware

netgear gs116e_firmware