VYPR
Unrated severityNVD Advisory· Published Mar 10, 2021· Updated Aug 4, 2024

CVE-2020-35231

CVE-2020-35231

Description

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The NSDP protocol on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 lacks authentication, letting attackers bypass access controls and fully compromise the switch.

Vulnerability

The NSDP (NETGEAR Switch Discovery Protocol) implementation on NETGEAR JGS516PE and GS116Ev2 switches running firmware version 2.6.0.43 does not require authentication. All configuration and management actions performed over NSDP are accepted from any network source without verifying the identity of the requester [1]. This effectively bypasses the intended access controls of the device.

Exploitation

An attacker need only be able to send packets to the switch's management interface (typically on the local network). No authentication credentials, prior access, or user interaction are required. By sending specially crafted NSDP protocol messages, the attacker can perform any action exposed through that interface, including reading and writing device configuration [1].

Impact

Successful exploitation grants the attacker full administrative control over the switch. The attacker can read sensitive configuration data, modify settings (including VLAN and port configurations), and potentially disrupt network operations or pivot to other devices on the network. The compromise is at the highest privilege level on the device, with no restrictions [1].

Mitigation

As of the publication of the advisory on March 8, 2021, no firmware update was available from NETGEAR. The advisory recommends restricting network access to the management interface (e.g., via VLAN segmentation or firewall rules) until a patched firmware version is released [1]. Users should monitor NETGEAR's support portal for updates.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.