Junglewise Threat Intelligence

CVE-2020-26919: Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

CVE-2020-26919 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: NETGEAR.

Executive brief

Netgear JGS516PE devices are vulnerable to a lack of access control at the function level. This allows unauthenticated remote attackers to execute administrative functions on the device.

Affected products

  • Netgear JGS516PE firmware before 2.6.0.43

Timeline

  • 2020-10-09: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV entry