VYPR
Unrated severityNVD Advisory· Published Jun 18, 2020· Updated Aug 4, 2024

CVE-2020-14442

CVE-2020-14442

Description

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated command injection in multiple NETGEAR Orbi WiFi systems before firmware 3.2.15.25 allows remote code execution.

Vulnerability

A pre-authentication command injection vulnerability exists in several NETGEAR Orbi WiFi system models. Affected devices include RBK752, RBK753, RBK753S, RBR750, RBS750, RBK842, RBR840, RBS840, RBK852, RBK853, RBR850, and RBS850 running firmware versions prior to 3.2.15.25. The injection occurs in an unspecified component reachable without prior authentication, allowing an attacker to supply crafted input that is executed as operating system commands by the device [1].

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending specially crafted network requests to the affected device. No authentication or user interaction is required. The attacker only needs network access to the vulnerable device, which is typical for remote exploitation [1]. Specific steps and the exact input vector are not disclosed in the available references, but the issue is classified as a pre-authentication command injection, implying the vulnerable code path is accessible before login.

Impact

Successful exploitation enables an unauthenticated attacker to execute arbitrary commands on the underlying operating system with elevated privileges. This can lead to complete compromise of the device, including full information disclosure, modification of system settings, and potentially using the device as a pivot for further attacks on the network. The confidentiality, integrity, and availability of the device are all at risk [1].

Mitigation

NETGEAR has released firmware version 3.2.15.25 for all affected models to address this vulnerability [1]. Users are strongly advised to download and install the latest firmware from NETGEAR Support as soon as possible. No workarounds are provided; installing the patched firmware is the only mitigation. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • NETGEAR/devicesdescription
  • Netgear/RBK752llm-fuzzy
    Range: <3.2.15.25

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.