CVE-2019-20655

HIGH

NETGEAR XR500 and XR700 Firmware - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 48.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (2)
netgear/xr500_firmware < 2.3.2.56
netgear/xr700_firmware < 1.0.1.20
Published Apr 15, 2020
Tracked Since Feb 18, 2026