8.8

CVE-2019-20691

Certain NETGEAR devices are affected by CSRF. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.24, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150v1 before 1.0.0.42, EX6200 before 1.0.3.88, EX7000 before 1.0.0.66, and WN2500RPv2 before 1.0.1.54.

Data is provided by the National Vulnerability Database (NVD)
NetgearD3600 Firmware Version < 1.0.0.72
   NetgearD3600 Version-
NetgearD6000 Firmware Version < 1.0.0.72
   NetgearD6000 Version-
NetgearEx3700 Firmware Version < 1.0.0.70
   NetgearEx3700 Version-
NetgearEx3800 Firmware Version < 1.0.0.70
   NetgearEx3800 Version-
NetgearEx6000 Firmware Version < 1.0.0.30
   NetgearEx6000 Version-
NetgearEx6100 Firmware Version < 1.0.2.24
   NetgearEx6100 Version-
NetgearEx6120 Firmware Version < 1.0.0.40
   NetgearEx6120 Version-
NetgearEx6130 Firmware Version < 1.0.0.22
   NetgearEx6130 Version-
NetgearEx6150 Firmware Version < 1.0.0.42
   NetgearEx6150 Versionv1
NetgearEx6200 Firmware Version < 1.0.3.88
   NetgearEx6200 Version-
NetgearEx7000 Firmware Version < 1.0.0.66
   NetgearEx7000 Version-
NetgearWn2500rp Firmware Version < 1.0.1.54
   NetgearWn2500rp Versionv2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.435
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
cve@mitre.org 8.3 2.8 5.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.