CVE-2020-35801

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/12/2020
Last modified:
23/03/2021

Description

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. A TFTP server was found to be active by default. It allows remote authenticated users to update the switch firmware.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:jgs516pe_firmware:*:*:*:*:*:*:*:* 2.6.0.48 (excluding)
cpe:2.3:h:netgear:jgs516pe:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jgs524e_firmware:*:*:*:*:*:*:*:* 2.6.0.48 (excluding)
cpe:2.3:h:netgear:jgs524e:v2:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jgs524pe_firmware:*:*:*:*:*:*:*:* 2.6.0.48 (excluding)
cpe:2.3:h:netgear:jgs524pe:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:gs116e_firmware:*:*:*:*:*:*:*:* 2.6.0.48 (excluding)
cpe:2.3:h:netgear:gs116e:v2:*:*:*:*:*:*:*