CVE-2019-20703

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
6.3 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.0/AC:L/AV:A/A:H/C:N/I:L/PR:L/S:U/UI:N
CVEADP
---
---