CVE-2019-20647
Description
NETGEAR RAX40 devices before 1.0.3.64 are affected by denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NETGEAR RAX40 routers before firmware 1.0.3.64 are vulnerable to a denial of service attack from an adjacent network with low privileges.
Vulnerability
A denial of service vulnerability exists in NETGEAR RAX40 routers running firmware versions prior to 1.0.3.64. The specific nature of the flaw is not publicly detailed, but it affects the device's ability to process certain network traffic, leading to a crash or hang. Affected models include RAX40 with firmware before 1.0.3.64 [1].
Exploitation
An attacker must be on the same adjacent network as the target device and have low-privileged access (e.g., guest credentials). No user interaction is required. The attack vector is low complexity, and the exploit sequence likely involves sending crafted packets to the router, causing it to become unresponsive [1].
Impact
Successful exploitation results in a denial of service, making the router unavailable for legitimate network traffic. The impact is limited to availability, with no effect on confidentiality or integrity. The scope is changed, meaning the vulnerable component is different from the impacted system (the router's network services) [1].
Mitigation
NETGEAR has released firmware version 1.0.3.64 to address this vulnerability. Users are strongly advised to upgrade to this version or later via the NETGEAR support page. No workarounds are available [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- NETGEAR/RAX40description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- kb.netgear.com/000061495/Security-Advisory-for-Denial-of-Service-on-RAX40-PSV-2019-0210mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.