CVE-2019-20672
Description
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in certain NETGEAR WiFi system models (RBR50, RBS50, RBK50) prior to firmware 2.3.5.30 allows authenticated admin-level attackers to inject malicious scripts.
Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in the web interface of NETGEAR RBR50, RBS50, and RBK50 devices running firmware versions prior to 2.3.5.30 [1]. An authenticated user with administrative privileges can inject arbitrary JavaScript code that is stored on the device and later executed in the browser of other admin users when they access certain pages.
Exploitation
An attacker must have valid admin credentials to the affected device's web interface. Once authenticated, the attacker can inject malicious script code into a configuration field that is not properly sanitized. This stored payload is then served to any other admin user who views the affected page, triggering the XSS in their browser [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of an admin user's session, leading to potential information disclosure (confidentiality) and unauthorized modification of settings (integrity) [1]. The CVSS v3 vector indicates high impact on confidentiality and integrity, with a base score of 6.0 (Medium).
Mitigation
NETGEAR has released firmware version 2.3.5.30 to address this vulnerability. Users should immediately upgrade their devices to this version or later by downloading the firmware from NETGEAR Support and following the installation instructions [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/RBR50description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.