Skip to content
COOEY

EXPOSURES › CVE-2020-26919

CVE-2020-26919

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-26919 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Netgear JGS516PE devices lack function-level access controls, allowing unauthorized access to system functions.

The missing access control vulnerability in Netgear JGS516PE devices allows attackers to bypass intended security boundaries and execute arbitrary actions on the device. For DIB organizations, this represents a significant compliance risk as it violates the principle of least privilege and could lead to unauthorized network access or data exfiltration. Organizations must ensure all network hardware is patched and access controls are properly implemented to prevent such exploitable gaps.

Shame score — A missing access control vulnerability in a widely deployed consumer/enterprise router exposes the device to unauthorized manipulation, indicating a fundamental design or implementation flaw that was not mitigated by a patch before exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Netgear JGS516PE devices contain a missing function level access control vulnerability.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Netgear failed to implement proper access controls, leaving devices vulnerable to unauthorized access and potential exploitation.
cooey ↗ severe-fallout -0.60
Netgear failed to implement proper access controls, leaving devices vulnerable to unauthorized access and potential exploitation.
"Netgear JGS516PE devices contain a missing function level access control vulnerability."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.