VYPR
Unrated severityNVD Advisory· Published Dec 29, 2020· Updated Aug 4, 2024

CVE-2020-35826

CVE-2020-35826

Description

Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple NETGEAR routers and WiFi systems are vulnerable to stored cross-site scripting (XSS) before specific firmware versions, enabling script injection.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the web-based management interface of multiple NETGEAR routers and WiFi systems. The affected models include D7800 (before 1.0.1.56), R7500v2 (before 1.0.3.46), R7800 (before 1.0.2.74), R8900 (before 1.0.4.28), R9000 (before 1.0.4.28), RAX120 (before 1.0.0.78), RBK50 (before 2.3.5.30), RBR50 (before 2.3.5.30), RBS50 (before 2.3.5.30), XR500 (before 2.3.2.56), and XR700 (before 1.0.1.10). The vulnerability allows an attacker to inject malicious scripts that are stored on the device and executed when other users access the affected page [1].

Exploitation

An attacker with network access to the device's web-based management interface can exploit this vulnerability by injecting malicious JavaScript into input fields that are not properly sanitized. The injected script is then stored and executed in the context of the admin interface when other authenticated users view the affected page. The exact input vector is not disclosed, but typical stored XSS vectors include configuration parameters, device name fields, or other user-supplied data [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the affected device's web interface. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. The impact is limited to the web interface and does not directly affect the device's routing functions, but it can compromise administrative accounts and enable further attacks [1].

Mitigation

NETGEAR has released firmware updates that fix this vulnerability. Users should update to the following versions or later: D7800 1.0.1.56, R7500v2 1.0.3.46, R7800 1.0.2.74, R8900 1.0.4.28, R9000 1.0.4.28, RAX120 1.0.0.78, RBK50 2.3.5.30, RBR50 2.3.5.30, RBS50 2.3.5.30, XR500 2.3.2.56, and XR700 1.0.1.10. No workarounds are available; updating firmware is the only recommended mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.