VYPR
Unrated severityNVD Advisory· Published Mar 10, 2021· Updated Aug 4, 2024

CVE-2020-35223

CVE-2020-35223

Description

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The CSRF protection on NETGEAR JGS516PE/GS116Ev2 switches can be bypassed by omitting the token parameter, allowing unauthorized actions.

Vulnerability

The CSRF protection mechanism in the web administration panel of NETGEAR JGS516PE and GS116Ev2 switches running firmware version v2.6.0.43 can be bypassed by simply omitting the CSRF token parameter from HTTP requests [1]. This flaw allows an attacker to perform actions on behalf of an authenticated administrator without the need for a valid token.

Exploitation

An attacker must trick an authenticated administrator into clicking a crafted link or visiting a malicious page that sends an HTTP request to the switch's management interface without the CSRF token parameter. No prior authentication or network access is required beyond the ability to deliver the request to the victim's browser. The attack does not require user interaction beyond the initial click.

Impact

Successful exploitation enables the attacker to execute arbitrary administrative actions on the switch, such as modifying configuration settings, changing passwords, or enabling backdoor access. This can lead to full compromise of the network segment managed by the switch, potentially affecting confidentiality, integrity, and availability of network traffic.

Mitigation

No official patch or firmware update has been disclosed in the available references [1]. As a workaround, administrators should restrict access to the web management interface to trusted networks only, use VPNs for remote management, and monitor for unauthorized configuration changes. The device may be end-of-life; consult NETGEAR support for further guidance.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.