CVE-2019-20678
Description
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NETGEAR Orbi WiFi systems are vulnerable to stored XSS before firmware versions 2.3.5.26 or 2.3.5.30.
Vulnerability
The devices are affected by a stored cross-site scripting (XSS) vulnerability in the web management interface. This affects the following Orbi models and firmware versions: RBK20, RBR20, RBS20 before firmware 2.3.5.26; and RBK40, RBR40, RBS40, RBK50, RBR50, RBS50 before firmware 2.3.5.30 [1]. The vulnerability exists in the firmware's handling of user-supplied input that is later rendered in the administrative interface.
Exploitation
An attacker must have an authenticated session on the target device's web interface or trick an authenticated administrator into performing actions that inject malicious script. The attacker supplies crafted input that, when stored and subsequently viewed by another administrator, executes arbitrary JavaScript in the context of the management interface.
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript within the context of the victim's browser session. This could lead to session hijacking, defacement of the management interface, or redirection to malicious sites. The attacker does not gain direct control over the router itself but can perform actions the victim administrator is authorized to do.
Mitigation
NETGEAR released fixed firmware versions 2.3.5.26 for the RBK20, RBR20, RBS20 models and version 2.3.5.30 for the RBK40, RBR40, RBS40, RBK50, RBR50, RBS50 models. Users should update to the latest firmware via the NETGEAR Support page [1]. No workaround is available; upgrading is the only mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.