CVE-2020-14435
Summary
| CVE | CVE-2020-14435 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-18 17:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.2.104, SRS60 before 2.5.2.104, SRR60 before 2.5.2.104, SRK60B03 before 2.5.2.104, SRK60B04 before 2.5.2.104, SRK60B05 before 2.5.2.104, and SRK60B06 before 2.5.2.104. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Srk60 | - | All | All | All |
| Hardware | Netgear | Srk60 | - | All | All | All |
| Hardware | Netgear | Srk60b03 | - | All | All | All |
| Hardware | Netgear | Srk60b03 | - | All | All | All |
| Operating System | Netgear | Srk60b03 Firmware | All | All | All | All |
| Operating System | Netgear | Srk60b03 Firmware | All | All | All | All |
| Hardware | Netgear | Srk60b04 | - | All | All | All |
| Hardware | Netgear | Srk60b04 | - | All | All | All |
| Operating System | Netgear | Srk60b04 Firmware | All | All | All | All |
| Operating System | Netgear | Srk60b04 Firmware | All | All | All | All |
| Hardware | Netgear | Srk60b05 | - | All | All | All |
| Hardware | Netgear | Srk60b05 | - | All | All | All |
| Operating System | Netgear | Srk60b05 Firmware | All | All | All | All |
| Operating System | Netgear | Srk60b05 Firmware | All | All | All | All |
| Hardware | Netgear | Srk60b06 | - | All | All | All |
| Hardware | Netgear | Srk60b06 | - | All | All | All |
| Operating System | Netgear | Srk60b06 Firmware | All | All | All | All |
| Operating System | Netgear | Srk60b06 Firmware | All | All | All | All |
| Operating System | Netgear | Srk60 Firmware | All | All | All | All |
| Operating System | Netgear | Srk60 Firmware | All | All | All | All |
| Hardware | Netgear | Srr60 | - | All | All | All |
| Hardware | Netgear | Srr60 | - | All | All | All |
| Operating System | Netgear | Srr60 Firmware | All | All | All | All |
| Operating System | Netgear | Srr60 Firmware | All | All | All | All |
| Hardware | Netgear | Srs60 | - | All | All | All |
| Hardware | Netgear | Srs60 | - | All | All | All |
| Operating System | Netgear | Srs60 Firmware | All | All | All | All |
| Operating System | Netgear | Srs60 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Pre-Authentication Command Injection on Some WiFi Systems, PSV-2020-0026 | Answer | NETGEAR Support | CONFIRM | kb.netgear.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.