CVE-2019-20762 describes a buffer overflow vulnerability affecting numerous NETGEAR router models, including the D8500, R8500, and R8000, among others. An authenticated attacker on the local network can exploit this flaw to achieve high impact on confidentiality, integrity, and availability. While the CVSS score is 6.8 (MEDIUM), indicating a significant risk, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Organizations should prioritize patching affected devices to mitigate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.3.43CPE matchmatch criteria | cpe:2.3:o:netgear:d8500_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.2.128CPE matchmatch criteria | cpe:2.3:o:netgear:r8500_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.2.128CPE matchmatch criteria | cpe:2.3:o:netgear:r8300_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.4.28CPE matchmatch criteria | cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.68CPE matchmatch criteria | cpe:2.3:o:netgear:r7300dst_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.