CVE-2020-14436
Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, RBS850 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, and RBS840 before 3.2.15.25.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Pre-authentication command injection in multiple NETGEAR WiFi systems allows unauthenticated remote attackers to execute arbitrary commands.
Vulnerability
A pre-authentication command injection vulnerability exists in several NETGEAR Orbi WiFi system models. The flaw resides in the firmware of the affected devices, allowing an unauthenticated attacker to inject arbitrary commands. Affected models include RBK752, RBK753, RBK753S, RBR750, RBS750, RBK852, RBK853, RBR850, RBS850, RBK842, RBR840, and RBS840 running firmware versions prior to 3.2.15.25 [1].
Exploitation
An unauthenticated attacker can exploit this vulnerability remotely without any prior authentication or user interaction. The attacker sends specially crafted network requests to the vulnerable device, which fails to properly sanitize input, leading to command injection. No special network position is required beyond network access to the device [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands on the affected device with elevated privileges. This can lead to full compromise of the WiFi system, including potential data exfiltration, further network attacks, and persistent control [1].
Mitigation
NETGEAR has released firmware version 3.2.15.25 to fix this vulnerability. Users are strongly advised to download and install the latest firmware for their specific model from the NETGEAR Support website. No workarounds are provided; updating to the patched version is the only mitigation [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.