VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20662

CVE-2019-20662

Description

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in NETGEAR RBR50, RBS50, and RBK50 WiFi systems prior to firmware 2.3.5.30 allows authenticated admin users to inject malicious scripts.

Vulnerability

Stored cross-site scripting (XSS) vulnerability exists in the web interface of NETGEAR RBR50, RBS50, and RBK50 WiFi system devices running firmware versions prior to 2.3.5.30 [1]. The vulnerability allows an authenticated attacker with administrative privileges to inject malicious scripts that are stored on the device and executed in the context of other users accessing the management interface.

Exploitation

An attacker with administrative access to the device's web management interface can craft a payload and submit it via input fields that are not properly sanitized [1]. The script is then stored and executed when other authenticated users view the affected page. No user interaction is required beyond the initial injection step.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to disclosure of sensitive information (e.g., session cookies, configuration data) and modification of device settings [1]. The CVSS v3 score is 6.0 (Medium) with high impacts on confidentiality and integrity, but no impact on availability.

Mitigation

NETGEAR released firmware version 2.3.5.30 to address this vulnerability. Users should update their devices to this version or later [1]. No workarounds are provided; installing the latest firmware is the recommended mitigation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.