CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-35782

HIGH
8.1
CVSS Severity Score
EPSS Score0.0810%
EPSS Percentile1.94th
Published2020年12月30日
Last Modified2024年11月21日

Vulnerability Description

Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory.

Affected Platforms (CPE)

💻
Netgear

Jgs516pe Firmware

< 2.6.0.48
💻
Netgear

Jgs524e Firmware

< 2.6.0.48
💻
Netgear

Jgs524pe Firmware

< 2.6.0.48
💻
Netgear

Gs116e Firmware

< 2.6.0.48

References & Advisories

相關漏洞威脅