VYPR

JGS516PE/GS116Ev2

by Netgear

CVEs (8)

  • CVE-2020-35229HigMar 10, 2021
    risk 0.57cvss 8.8epss 0.01

    The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain…

  • CVE-2020-35223HigMar 10, 2021
    risk 0.57cvss 8.8epss 0.01

    The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.

  • CVE-2020-35221HigMar 10, 2021
    risk 0.57cvss 8.8epss 0.00

    The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some…

  • CVE-2020-35227HigMar 10, 2021
    risk 0.47cvss 7.2epss 0.01

    A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.

  • CVE-2020-35226HigMar 10, 2021
    risk 0.46cvss 7.1epss 0.01

    NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.

  • CVE-2020-35230MedMar 10, 2021
    risk 0.44cvss 6.8epss 0.00

    Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer parameters sent through the web server can be abused to cause a denial of service attack.

  • CVE-2020-35233MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.01

    The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.

  • CVE-2020-35228MedMar 10, 2021
    risk 0.31cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.