Security readout for executives and security teams
Plain-English summary
CVE-2019-20738 is a stored cross-site scripting issue in multiple NETGEAR routers, gateways, WiFi systems, and extenders. If an affected device remains on older firmware, attacker-supplied script content could persist and run when a user views the affected interface. Business urgency is moderate because impact is limited but network edge devices are often overlooked.
Executive priority
Handle through normal vulnerability remediation, with higher priority for exposed office or branch network devices. This is not KEV-listed in the bundle, but outdated perimeter and WiFi infrastructure can create avoidable security and operational risk.
Technical view
The CVSS v3.0 vector is 5.2: adjacent-network attack vector, low complexity, no privileges, user interaction required, changed scope, and low confidentiality and integrity impact. The CVE names many NETGEAR models with firmware versions fixed by later releases. It may relate to an incomplete fix for CVE-2017-18866.
Likely exposure
Exposure is most likely in small office, branch, home-office, or legacy environments still running listed NETGEAR models below the fixed firmware versions. The bundle does not identify cloud services or enterprise software exposure; the issue is tied to device firmware.
Exploitation context
The source bundle does not state active exploitation, and CISA KEV status is false. CVSS indicates exploitation requires adjacent network access and user interaction. Treat this as a credible device-management risk, not evidence of internet-scale exploitation from the supplied sources.
Researcher notes
Evidence is limited to the CVE record and NETGEAR advisory reference. The CVE provides affected models, fixed version thresholds, CVSS details, and a note about possible incomplete remediation of CVE-2017-18866. No CWE, proof-of-concept, or active exploitation evidence is included.
Mitigation direction
- Inventory NETGEAR devices and identify exact model and firmware version.
- Upgrade affected devices to the fixed firmware version or later.
- Use the NETGEAR advisory to confirm the correct firmware for each model.
- Check vendor guidance for unsupported or end-of-life devices.
- Prioritize devices in offices, branches, or shared network environments.
Validation and detection
- Compare discovered firmware versions against the CVE affected-version list.
- Confirm each upgraded device reports the expected fixed firmware version.
- Review device inventory for any listed models missed by central asset tools.
- Verify remediation records include model, firmware, date, and owner.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-20738 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.2 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AC:L/AV:A/A:N/C:L/I:L/PR:N/S:C/UI:R
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AC:L/AV:A/A:N/C:L/I:L/PR:N/S:C/UI:R2.12.7Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
5.2MediumVector: CVSS:3.0/AC:L/AV:A/A:N/C:L/I:L/PR:N/S:C/UI:R
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.netgear.com/000061187/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Routers-Gateways-and-WiFi-System-PSV-2016-0100CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
