VYPR
Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Aug 5, 2024

CVE-2019-20680

CVE-2019-20680

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R6900v2 before 1.2.0.36, R7000 before 1.0.9.60, R7000P before 1.3.1.64, R7800 before 1.0.2.60, R7900 before 1.0.3.8, R7900P before 1.4.1.30, R8000 before 1.0.4.46, R8000P before 1.4.1.30, R8300 before 1.0.2.128, R8500 before 1.0.2.128, R8900 before 1.0.4.12, R9000 before 1.0.4.12, and XR500 before 2.3.2.32.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated command injection in multiple NETGEAR routers and gateways allows attackers to execute arbitrary commands.

Vulnerability

A command injection vulnerability exists in the web-based management interface of multiple NETGEAR routers and gateways. An authenticated user can inject arbitrary commands through a vulnerable input field. Affected models include D7000v2 (before 1.0.0.53), R6220 (before 1.1.0.80), R6260 (before 1.1.0.64), R6700 (before 1.0.2.6), R6700v2 (before 1.2.0.36), R6800 (before 1.2.0.36), R6900 (before 1.0.2.4), R6900P (before 1.3.1.64), R6900v2 (before 1.2.0.36), R7000 (before 1.0.9.60), R7000P (before 1.3.1.64), R7800 (before 1.0.2.60), R7900 (before 1.0.3.8), R7900P (before 1.4.1.30), R8000 (before 1.0.4.46), R8000P (before 1.4.1.30), R8300 (before 1.0.2.128), R8500 (before 1.0.2.128), R8900 (before 1.0.4.12), R9000 (before 1.0.4.12), and XR500 (before 2.3.2.32) [1].

Exploitation

An attacker must first authenticate to the device's web interface with valid administrative credentials. By sending specially crafted HTTP requests containing command injection payloads to vulnerable endpoints, the attacker can execute arbitrary operating system commands on the device [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the affected device. This can lead to full compromise of the router, including data exfiltration, modification of configuration, and use as a pivot for further network attacks [1].

Mitigation

NETGEAR has released firmware updates for all affected devices. Users should upgrade to the latest firmware version for their specific model as listed in the security advisory [1]. No workaround is available; patching is the only mitigation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.