VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20661

CVE-2019-20661

Description

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in NETGEAR RBR50, RBS50, and RBK50 WiFi systems before firmware 2.3.5.30 allows authenticated attackers to inject malicious scripts.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in certain NETGEAR WiFi systems: RBR50, RBS50, and RBK50 running firmware versions prior to 2.3.5.30 [1]. The vulnerability is present in the web-based management interface, allowing an authenticated user to inject malicious scripts that are stored and later executed in the context of other users' sessions [1].

Exploitation

An attacker with authenticated access (e.g., admin or user credentials) can inject a crafted payload into a vulnerable input field of the web interface. The payload persists on the device and is executed when other users access the affected page [1]. No user interaction beyond normal browsing is required for the stored script to execute.

Impact

Successful exploitation leads to stored XSS, which can result in disclosure of sensitive information or unauthorized actions performed on behalf of the victim. The CVSS v3 vector indicates a local attack vector, high privileges required, no user interaction, and potential for high confidentiality and integrity impact [1].

Mitigation

NETGEAR has released firmware version 2.3.5.30 to fix the vulnerability for RBR50, RBS50, and RBK50 [1]. Users should update to the latest firmware via the NETGEAR Support page [1]. No workaround other than updating is mentioned.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.