CVE-2019-20676 describes a lack of function-level access control vulnerability affecting numerous NETGEAR devices, including various FS, GS, JGS, and XS series switches. This medium-severity vulnerability (CVSS 6.0) allows a highly privileged attacker with local access to compromise confidentiality and integrity without user interaction. While the exploit intelligence indicates no public exploits, Metasploit modules, or Nuclei templates, the vulnerability's low EPSS score and lack of community discussion or media coverage suggest it is not widely known or actively exploited. Organizations using affected NETGEAR devices should consult vendor advisories for patching information.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.1.26CPE matchmatch criteria | cpe:2.3:o:netgear:fs728tlp_firmware:*:*:*:*:*:*:*:* | ||
< 1.6.0.4CPE matchmatch criteria | cpe:2.3:o:netgear:gs105e_firmware:*:*:*:*:*:*:*:* | ||
< 1.6.0.4CPE matchmatch criteria | cpe:2.3:o:netgear:gs105pe_firmware:*:*:*:*:*:*:*:* | ||
< 2.06.08CPE matchmatch criteria | cpe:2.3:o:netgear:gs108e_firmware:*:*:*:*:*:*:*:* | ||
< 2.06.08CPE matchmatch criteria | cpe:2.3:o:netgear:gs108pe_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.