VYPR
Unrated severityNVD Advisory· Published Dec 29, 2020· Updated Aug 4, 2024

CVE-2020-35802

CVE-2020-35802

Description

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.14, RBW30 before 2.6.1.4, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, and RBS40V before 2.6.1.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple NETGEAR routers and WiFi systems are vulnerable to sensitive information disclosure before their fixed firmware versions.

Vulnerability

A sensitive information disclosure vulnerability exists in multiple NETGEAR devices, including CBR40, RBW30, RAX75, RAX80, RBS40V, and various Orbi WiFi system models (RBK752, RBR750, RBS750, RBK852, RBR850, RBS850, RBK842, RBR840, RBS840). The vulnerable firmware versions are: CBR40 before 2.5.0.14, RBW30 before 2.6.1.4, RAX75 and RAX80 before 1.0.3.102, Orbi models before 3.2.16.6, and RBS40V before 2.6.1.4 [1]. The exact nature of the sensitive information exposed and the vulnerable component are not disclosed in the available references.

Exploitation

Based on the official description [1], an attacker can exploit this vulnerability to access sensitive information. The required access level (e.g., network proximity, authentication status) and the specific attack vector are not detailed in the provided references. No publicly available exploit details or proof-of-concept have been disclosed.

Impact

Successful exploitation leads to the disclosure of sensitive information from the affected NETGEAR device. The specific type of information (e.g., credentials, configuration data, network details) is not specified in the references [1]. The confidentiality impact is partial, and there is no indication of integrity or availability impact.

Mitigation

NETGEAR has released fixed firmware versions for all affected products: CBR40 firmware version 2.5.0.14, RBW30 and RBS40V firmware version 2.6.1.4, RAX75 and RAX80 firmware version 1.0.3.102, and Orbi models (RBK752, RBR750, RBS750, RBK852, RBR850, RBS850, RBK842, RBR840, RBS840) firmware version 3.2.16.6 [1]. Users should download and install the latest firmware from NETGEAR Support as soon as possible. No workarounds are provided for unpatched versions.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

15

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.