CVE-2019-20709

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
7.1 HIGH
ADJACENT_NETWORK
HIGH
LOW
CVSS:3.0/AC:H/AV:A/A:H/C:H/I:H/PR:L/S:U/UI:N
CVEADP
---
---