VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20665

CVE-2019-20665

Description

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR Orbi WiFi systems are vulnerable to stored cross-site scripting (XSS) before firmware versions 2.3.5.26 or 2.3.5.30, allowing attackers to execute arbitrary script in the web interface.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the web interface of certain NETGEAR Orbi WiFi system models. Affected devices include the RBR20, RBS20, and RBK20 running firmware versions prior to 2.3.5.26, as well as the RBR40, RBS40, RBK40, RBR50, RBS50, and RBK50 running firmware versions prior to 2.3.5.30 [1]. The vulnerability is triggered when a user accesses a stored page or setting containing injected malicious script.

Exploitation

An attacker with access to the device's web interface—potentially through a compromised administrator session or by tricking an authenticated user—can inject a malicious script into a stored field (e.g., device name or other configuration parameter). The script then automatically executes when an administrator or other user views the affected page [1]. No additional authentication beyond the stored session is required for the script to fire.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the web interface, leading to potential theft of session cookies, modification of device settings, or further attacks within the local network. The impact is limited to actions the authenticated user can perform; however, because the script runs in the browser of an administrative user, it can compromise the management functionality of the device [1].

Mitigation

NETGEAR has released fixed firmware versions: 2.3.5.26 for RBR20, RBS20, and RBK20; and 2.3.5.30 for RBR40, RBS40, RBK40, RBR50, RBS50, and RBK50 [1]. Users should update their devices to these or later firmware versions immediately. No workarounds are provided; the only mitigation is to apply the firmware update [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.