CVE-2020-35231
Description
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The NSDP protocol on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 lacks authentication, letting attackers bypass access controls and fully compromise the switch.
Vulnerability
The NSDP (NETGEAR Switch Discovery Protocol) implementation on NETGEAR JGS516PE and GS116Ev2 switches running firmware version 2.6.0.43 does not require authentication. All configuration and management actions performed over NSDP are accepted from any network source without verifying the identity of the requester [1]. This effectively bypasses the intended access controls of the device.
Exploitation
An attacker need only be able to send packets to the switch's management interface (typically on the local network). No authentication credentials, prior access, or user interaction are required. By sending specially crafted NSDP protocol messages, the attacker can perform any action exposed through that interface, including reading and writing device configuration [1].
Impact
Successful exploitation grants the attacker full administrative control over the switch. The attacker can read sensitive configuration data, modify settings (including VLAN and port configurations), and potentially disrupt network operations or pivot to other devices on the network. The compromise is at the highest privilege level on the device, with no restrictions [1].
Mitigation
As of the publication of the advisory on March 8, 2021, no firmware update was available from NETGEAR. The advisory recommends restricting network access to the management interface (e.g., via VLAN segmentation or firewall rules) until a patched firmware version is released [1]. Users should monitor NETGEAR's support portal for updates.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- NETGEAR/JGS516PE/GS116Ev2description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.