CVE-2019-20668
Description
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS vulnerability in multiple NETGEAR WiFi system models; fixed in firmware versions 2.3.5.26 or 2.3.5.30.
Vulnerability
Stored cross-site scripting (XSS) vulnerability exists in NETGEAR WiFi system models. Affected devices: RBR20, RBS20, RBK20 before firmware 2.3.5.26; and RBR40, RBS40, RBK40, RBR50, RBS50, RBK50 before firmware 2.3.5.30 [1]. The vulnerability allows an attacker to inject malicious scripts that are stored on the device.
Exploitation
An attacker with administrative access or ability to submit crafted input (e.g., via the web interface) can inject a stored XSS payload. The attacker may need to be on the local network or have valid credentials to access the management interface. The injected script executes in the context of the administrator's browser when viewing the affected page.
Impact
Successful exploitation leads to execution of arbitrary JavaScript in the context of the administrator's browser. This could result in disclosure of sensitive information, session hijacking, or unauthorized actions performed on the device. The impact is limited to the administration interface.
Mitigation
NETGEAR released fixed firmware versions: 2.3.5.26 for RBR20, RBS20, RBK20; and 2.3.5.30 for RBR40, RBS40, RBK40, RBR50, RBS50, RBK50 [1]. Users should update to these versions immediately. No workarounds are mentioned.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- NETGEAR/RBR20description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.