Security readout for executives and security teams
Plain-English summary
This is a stored cross-site scripting issue in specific NETGEAR Orbi WiFi systems. A highly privileged local attacker could affect sensitive data or settings through the device management interface. The listed impact is meaningful, but exposure is narrower than an internet-reachable remote flaw.
Executive priority
Treat this as a moderate-priority network device hygiene issue. Patch affected systems during the next maintenance window, faster for sensitive sites or weakly segmented networks.
Technical view
CVE-2019-20660 affects listed RBR/RBS/RBK20, 40, and 50 models before fixed firmware versions. CVSS 3.0 is 6.0 with AV:L, AC:L, PR:H, UI:N, C:H, I:H, A:N. No CWE is listed in the provided record.
Likely exposure
Exposure is likely limited to environments with affected NETGEAR systems running firmware below the versions named in the advisory. Risk is highest where administrative access or local management networks are weakly controlled.
Exploitation context
The source bundle does not identify active exploitation, and the CVE is not marked KEV. The CVSS vector requires local access and high privileges, which narrows likely exploitation compared with unauthenticated remote vulnerabilities.
Researcher notes
Evidence is limited to the CVE record and NETGEAR advisory. Do not assume broader NETGEAR product impact, active exploitation, or additional mitigations beyond vendor guidance from the provided sources.
Mitigation direction
- Update affected NETGEAR devices to the fixed firmware versions or later named by NETGEAR.
- Check NETGEAR advisory guidance before applying compensating controls or deployment changes.
- Restrict device administration to trusted management networks and authorized administrators.
- Remove or replace unsupported affected devices if current firmware cannot be applied.
Validation and detection
- Inventory NETGEAR RBR20, RBS20, RBK20, RBR40, RBS40, RBK40, RBR50, RBS50, and RBK50 devices.
- Compare installed firmware against 2.3.5.26 for 20-series and 2.3.5.30 for 40/50-series devices.
- Confirm administrative interfaces are not broadly reachable from untrusted local networks.
- Document updated firmware versions and exceptions requiring risk acceptance.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-20660 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AC:L/AV:L/A:N/C:H/I:H/PR:H/S:U/UI:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AC:L/AV:L/A:N/C:H/I:H/PR:H/S:U/UI:N0.85.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
6MediumVector: CVSS:3.0/AC:L/AV:L/A:N/C:H/I:H/PR:H/S:U/UI:N
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.netgear.com/000061479/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-WiFi-Systems-PSV-2018-0562CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
