CVE-2020-5621
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the device via unspecified vectors.
Affected (2)
Products: Netgear: Gs716tv2 Firmware, Gs724tv3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.4.2.30 |
| Running on/with | Platform Versions |
|---|---|
Netgear Gs716t | Version v2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.4.2.30 |
| Running on/with | Platform Versions |
|---|---|
Netgear Gs724t | Version v3 |
References (8)
Source: vultures@jpcert.or.jp
PatchVendor Advisory
Source: vultures@jpcert.or.jp
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.