Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory.

Project Subscriptions

Vendors Products
Netgear Subscribe
Gs116e Firmware Subscribe
Jgs516pe Subscribe
Jgs516pe Firmware Subscribe
Jgs524e Subscribe
Jgs524e Firmware Subscribe
Jgs524pe Subscribe
Jgs524pe Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-23437 Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:09:15.186Z

Reserved: 2020-12-29T00:00:00

Link: CVE-2020-35782

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-30T00:15:13.207

Modified: 2024-11-21T05:28:04.850

Link: CVE-2020-35782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses