← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-26913

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.63, R7800 before 1.0.2.60, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, RBK40 before 2.3.0.28, RBR40 before 2.3.0.28, RBS40 before 2.3.0.28, SRK60 before 2.2.2.20, SRR60 before 2.2.2.20, SRS60 before 2.2.2.20, WN3000RPv2 before 1.0.0.78, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, WNR2000v5 before 1.0.0.70, XR450 before 2.3.2.40, and XR500 before 2.3.2.40.

No Active Exploit Signals
CVSS Base Score
6.8
MEDIUM
Exploitability:1.0
Impact Score:5.9
EPSS Probability:0.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
netgear d6100_firmware all
netgear d6100 all
netgear r7800_firmware all
netgear r7800 all
netgear r8900_firmware all
netgear r8900 all
netgear r9000_firmware all
netgear r9000 all
netgear rbk20_firmware all
netgear rbk20 all
netgear rbr20_firmware all
netgear rbr20 all
netgear rbs20_firmware all
netgear rbs20 all
netgear rbk50_firmware all
netgear rbk50 all
netgear rbr50_firmware all
netgear rbr50 all
netgear rbs50_firmware all
netgear rbs50 all
netgear rbk40_firmware all
netgear rbk40 all
netgear rbs40_firmware all
netgear rbs40 all
netgear srk60_firmware all
netgear srk60 all
netgear srr60_firmware all
netgear srr60 all
netgear srs60_firmware all
netgear srs60 all
netgear wn3000rpv2_firmware all
netgear wn3000rpv2 all
netgear wndr4300v2_firmware all
netgear wndr4300v2 all
netgear wndr4500v3_firmware all
netgear wndr4500v3 all
netgear wnr2000v5_firmware all
netgear wnr2000v5 all
netgear xr450_firmware all
netgear xr450 all
netgear xr500_firmware all
netgear xr500 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.555%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-10-09T00:00:00
Published2020-10-09T06:30:57
Last Updated2024-08-04T16:03:22

LINK COPIED TO CLIPBOARD