← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-35782

Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory.

No Active Exploit Signals
CVSS Base Score
8.1
HIGH
Exploitability:2.9
Impact Score:5.2
EPSS Probability:1.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
netgear jgs516pe_firmware all
netgear jgs516pe all
netgear jgs524e_firmware all
netgear jgs524e v2
netgear jgs524pe_firmware all
netgear jgs524pe all
netgear gs116e_firmware all
netgear gs116e v2

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.639%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-12-29T00:00:00
Published2020-12-29T23:41:12
Last Updated2024-08-04T17:09:15

LINK COPIED TO CLIPBOARD