CVE-2019-20658
Last modified
CVE-2019-20658 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Certain NETGEAR devices are affected by disclosure of sensitive information. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS108Ev3 before 2.06.08, GS108PEv3 before 2.06.08, GS110EMX before 1.0.1.4, GS116Ev2 before 2.6.0.35, GS408EPP before 1.0.0.15, GS808E before 1.7.0.7, GS810EMX before 1.7.1.1, GS908E before 1.7.0.3, GSS108E before 1.6.0.4, GSS108EPP before 1.0.0.15, GSS116E before 1.6.0.9, JGS516PE before 2.6.0.35, JGS524Ev2 before 2.6.0.35, JGS524PE before 2.6.0.35, XS512EM before 1.0.1.1, XS708Ev2 before 1.6.0.23, XS716E before 1.6.0.23, and XS724EM before 1.0.1.1.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS108Ev3 before 2.06.08, GS108PEv3 before 2.06.08, GS110EMX before 1.0.1.4, GS116Ev2 before 2.6.0.35, GS408EPP before 1.0.0.15, GS808E before 1.7.0.7, GS810EMX before 1.7.1.1, GS908E before 1.7.0.3, GSS108E before 1.6.0.4, GSS108EPP before 1.0.0.15, GSS116E before 1.6.0.9, JGS516PE before 2.6.0.35, JGS524Ev2 before 2.6.0.35, JGS524PE before 2.6.0.35, XS512EM before 1.0.1.1, XS708Ev2 before 1.6.0.23, XS716E before 1.6.0.23, and XS724EM before 1.0.1.1.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Fs728tlp Firmware | < 1.0.1.26 |
| Netgear | Gs105e Firmware | < 1.6.0.4 |
| Netgear | Gs105pe Firmware | < 1.6.0.4 |
| Netgear | Gs108e Firmware | < 2.06.08 |
| Netgear | Gs108pe Firmware | < 2.06.08 |
| Netgear | Gs110emx Firmware | < 1.0.1.4 |
| Netgear | Gs116e Firmware | < 2.6.0.35 |
| Netgear | Gs408epp Firmware | < 1.0.0.15 |
| Netgear | Gs808e Firmware | < 1.7.0.7 |
| Netgear | Gs810emx Firmware | < 1.7.1.1 |
| Netgear | Gs908e Firmware | < 1.7.0.3 |
| Netgear | Gss108e Firmware | < 1.6.0.4 |
| Netgear | Gss108epp Firmware | < 1.0.0.15 |
| Netgear | Gss116e Firmware | < 1.6.0.9 |
| Netgear | Jgs516pe Firmware | < 2.6.0.35 |
| Netgear | Jgs524e Firmware | < 2.6.0.35 |
| Netgear | Jgs524pe Firmware | < 2.6.0.35 |
| Netgear | Xs512em Firmware | < 1.0.1.1 |
| Netgear | Xs708e Firmware | < 1.6.0.23 |
| Netgear | Xs716e Firmware | < 1.6.0.23 |
| Netgear | Xs724em Firmware | < 1.0.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-20658?
How severe is CVE-2019-20658?
How do I fix CVE-2019-20658?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-20652NETGEAR WAC505 devices before 8.2.1.16 are affected by discl…6.5
- CVE-2019-20653Certain NETGEAR devices are affected by denial of service. T…6.5
- CVE-2019-20654Certain NETGEAR devices are affected by incorrect configurat…7.5
- CVE-2019-20655Certain NETGEAR devices are affected by command injection by…7.8
- CVE-2019-20656Certain NETGEAR devices are affected by a hardcoded password…8.8
- CVE-2019-20657Certain NETGEAR devices are affected by a buffer overflow by…8
- CVE-2019-20659Certain NETGEAR devices are affected by command injection by…7.2
- CVE-2019-2066In libxaac, there is a possible out of bounds write due to a…8.8
- CVE-2019-20660Certain NETGEAR devices are affected by stored XSS. This aff…4.8
- CVE-2019-20661Certain NETGEAR devices are affected by stored XSS. This aff…4.8
- CVE-2019-20662Certain NETGEAR devices are affected by stored XSS. This aff…4.3
- CVE-2019-20663Certain NETGEAR devices are affected by stored XSS. This aff…4.3
Are you affected by CVE-2019-20658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
