CVE-2019-20655

EUVD-2019-11194
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AC:L/AV:L/A:L/C:H/I:H/PR:L/S:U/UI:N