CVE-2020-35227

HIGH

Netgear Gs116e Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.

Scores

CVSS v3 7.2
EPSS 0.0056
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (2)
netgear/gs116e_firmware 2.6.0.43
netgear/jgs516pe_firmware 2.6.0.43
Published Mar 10, 2021
Tracked Since Feb 18, 2026