VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20675

CVE-2019-20675

Description

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR RBR50, RBS50, and RBK50 devices before firmware 2.3.5.30 are vulnerable to stored XSS, allowing authenticated admin to execute arbitrary scripts.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in certain NETGEAR WiFi system models: RBR50, RBS50, and RBK50 running firmware versions prior to 2.3.5.30 [1]. The vulnerability is present in the device's web management interface and can be exploited when an authenticated administrator with high privileges injects malicious script into the configuration parameters [1].

Exploitation

An attacker must have administrative access to the device to exploit this stored XSS vulnerability. Once authenticated, the attacker can inject a malicious script via the web interface, which is then stored and executed when other administrators view the affected page [1]. The attack vector is local (AV:L) and requires high privileges, but does not require user interaction [1].

Impact

Successful exploitation allows an attacker to execute arbitrary HTML and JavaScript in the context of the affected web interface, potentially leading to disclosure of sensitive information and compromise of the device's configuration [1]. The CVSS v3 vector indicates high impact on confidentiality and integrity, but no impact on availability [1].

Mitigation

NETGEAR has released firmware version 2.3.5.30 to fix this vulnerability. Users of RBR50, RBS50, and RBK50 should upgrade to this version immediately [1]. No workaround is provided; the only mitigation is to install the latest firmware [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.