VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20670

CVE-2019-20670

Description

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR Orbi WiFi systems (RBR50, RBS50, RBK50) prior to firmware 2.3.5.30 are vulnerable to stored cross-site scripting (XSS).

Vulnerability

Stored cross-site scripting (XSS) vulnerability affects NETGEAR Orbi WiFi system models RBR50, RBS50, and RBK50 running firmware versions prior to 2.3.5.30 [1]. The vulnerability is due to insufficient sanitization of user-controlled data that is later rendered in the web interface, allowing injection of arbitrary script code that persists across sessions [1].

Exploitation

To exploit this vulnerability, an attacker must have administrative access to the device's web interface via the local network [1]. Successful exploitation requires the attacker to inject a malicious script into a stored configuration field that is subsequently displayed to other administrators or users accessing the management interface [1]. No user interaction beyond normal administrative actions is required for the stored payload to execute.

Impact

An authenticated attacker who successfully exploits this vulnerability can execute arbitrary script code in the context of the affected web interface, potentially leading to session hijacking, credential theft, or manipulation of device settings [1]. The CVSS v3.0 score is 6.0 (Medium) with a vector of CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N, indicating high impact on confidentiality and integrity, but no impact on availability [1].

Mitigation

NETGEAR has released fixed firmware version 2.3.5.30 for all affected models (RBR50, RBS50, RBK50) [1]. Users are strongly recommended to download and install the latest firmware from NETGEAR Support as soon as possible [1]. No known workarounds exist; applying the firmware update is the only remediation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.