VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20641

CVE-2019-20641

Description

NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR RAX40 routers before firmware 1.0.3.64 lack function-level access controls, allowing an adjacent unauthenticated attacker to fully compromise the device.

Vulnerability

NETGEAR RAX40 routers running firmware versions prior to 1.0.3.64 are affected by a missing function-level access control vulnerability [1]. The bug exists in the firmware's handling of administrative functions; the device fails to properly enforce access controls on certain server-side functions, making them reachable without the required authentication or authorization checks.

Exploitation

An attacker must be on the same local network as the vulnerable RAX40 (adjacent network position) and send crafted requests to the affected functions. No authentication or user interaction is required. The attack complexity is low and no privileges are needed prior to exploitation [1]. The exact sequence of steps is not publicly detailed, but the CVSS vector indicates successful exploitation does not depend on any special conditions beyond network adjacency.

Impact

Successful exploitation leads to complete compromise of the device's confidentiality, integrity, and availability. The attacker can achieve high impact on all three CIA pillars: they can read sensitive data (e.g., configuration or credentials), modify system settings or firmware, and disrupt normal router operations [1]. The CVSS v3 score of 8.8 (High) reflects this full compromise potential.

Mitigation

NETGEAR released firmware version 1.0.3.64 to address this vulnerability [1]. Users must update the RAX40 firmware to 1.0.3.64 or later. The fix is available from NETGEAR Support. No workarounds are documented; the only mitigation is applying the patch. The CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of publication.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • NETGEAR/RAX40description
  • Netgear/RAX40llm-fuzzy
    Range: <1.0.3.64

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.