CVE-2020-26929

HIGH

NETGEAR R6220 and R6230 < 1.1.0.100 - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

Scores

CVSS v3 7.3
EPSS 0.0048
EPSS Percentile 65.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-77
Status published
Products (2)
netgear/r6220_firmware < 1.1.0.100
netgear/r6230_firmware < 1.1.0.100
Published Oct 09, 2020
Tracked Since Feb 18, 2026