Vulnerability Details CVE-2020-26920
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110, and SRS60 before 2.5.3.110.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 5.8
Products affected by CVE-2020-26920
-
cpe:2.3:h:netgear:srk60:-
-
cpe:2.3:h:netgear:srr60:-
-
cpe:2.3:h:netgear:srs60:-
-
cpe:2.3:o:netgear:srk60_firmware:2.2.0.64
-
cpe:2.3:o:netgear:srk60_firmware:2.2.1.210
-
cpe:2.3:o:netgear:srk60_firmware:2.2.2.20
-
cpe:2.3:o:netgear:srk60_firmware:2.3.5.106
-
cpe:2.3:o:netgear:srk60_firmware:2.5.2.104
-
cpe:2.3:o:netgear:srr60_firmware:2.2.0.64
-
cpe:2.3:o:netgear:srr60_firmware:2.2.1.210
-
cpe:2.3:o:netgear:srr60_firmware:2.2.2.20
-
cpe:2.3:o:netgear:srr60_firmware:2.3.5.106
-
cpe:2.3:o:netgear:srr60_firmware:2.5.1.106
-
cpe:2.3:o:netgear:srr60_firmware:2.5.2.104
-
cpe:2.3:o:netgear:srs60_firmware:2.2.0.64
-
cpe:2.3:o:netgear:srs60_firmware:2.2.1.210
-
cpe:2.3:o:netgear:srs60_firmware:2.2.2.20
-
cpe:2.3:o:netgear:srs60_firmware:2.3.5.106
-
cpe:2.3:o:netgear:srs60_firmware:2.5.1.106
-
cpe:2.3:o:netgear:srs60_firmware:2.5.2.104