VYPR
Unrated severityNVD Advisory· Published Oct 9, 2020· Updated Aug 4, 2024

CVE-2020-26920

CVE-2020-26920

Description

Unauthenticated command injection in NETGEAR Orbi Pro WiFi systems (SRK60, SRR60, SRS60) prior to firmware 2.5.3.110 allows full device compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated command injection in NETGEAR Orbi Pro WiFi systems (SRK60, SRR60, SRS60) prior to firmware 2.5.3.110 allows full device compromise.

Vulnerability

A pre-authentication command injection vulnerability exists in the firmware of certain NETGEAR Orbi Pro WiFi system models. The flaw resides in the handling of network requests by the device's management interface, allowing an unauthenticated attacker to inject arbitrary operating system commands. Affected models are SRK60, SRR60, and SRS60 running firmware versions prior to 2.5.3.110 [1]. No authentication or special configuration is required to reach the vulnerable code path.

Exploitation

An attacker with network access to the affected device (adjacent network, as per CVSS vector) can send a specially crafted request to the device's management interface. No prior authentication or user interaction is needed. The attacker crafts a request containing malicious command payloads that are not properly sanitized, leading to command injection [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the device. This results in full compromise of confidentiality, integrity, and availability (CVSS 8.8, High). The attacker can read sensitive data, modify device configuration, install malware, or disrupt network services [1].

Mitigation

NETGEAR has released firmware version 2.5.3.110 to address this vulnerability. Users should immediately update their devices to this version or later via the NETGEAR Support page. No workarounds are available; updating is the only mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.