CVE-2020-14435
Estado: ModificadaAlta (8.8)—
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.2.104, SRS60 before 2.5.2.104, SRR60 before 2.5.2.104, SRK60B03 before 2.5.2.104, SRK60B04 before 2.5.2.104, SRK60B05 before 2.5.2.104, and SRK60B06 before 2.5.2.104.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.00%
- Percentil entre todas las CVEs puntuadas: 62
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-77
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-14435",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-06-18T17:15:12.640",
"references": [
{
"url": "https://kb.netgear.com/000061930/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2020-0026",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://kb.netgear.com/000061930/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2020-0026",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.2.104, SRS60 before 2.5.2.104, SRR60 before 2.5.2.104, SRK60B03 before 2.5.2.104, SRK60B04 before 2.5.2.104, SRK60B05 before 2.5.2.104, and SRK60B06 before 2.5.2.104."
},
{
"lang": "es",
"value": "Determinados dispositivos NETGEAR están afectados por una inyección de comandos por parte de un atacante no autenticado. Esto afecta a SRK60 antes de 2.5.2.104, SRS60 antes de 2.5.2.104, SRR60 antes de 2.5.2.104, SRK60B03 antes de 2.5.2.104, SRK60B04 antes de 2.5.2.104, SRK60B05 antes de 2.5.2.104 y SRK60B06 antes de 2.5.2.104"
}
],
"lastModified": "2026-06-17T02:54:46.040",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srk60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56813F5F-CF4B-4A6C-B187-D935A2768D91",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srk60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DCC347EB-699E-4626-A944-2D378101DDCF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srs60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E16D818A-5988-4B9D-9083-3070BCF35939",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srs60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BFB01247-A20F-41CA-8718-E8E60E7F14B3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srr60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2421F159-B182-4E57-90CA-6D4D19FDD7D9",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srr60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "55E6F589-04DA-431C-9E03-BA2A59BB0E4A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srk60b03_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2CA07F1F-EB90-49A7-97A1-D13DC0083A89",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srk60b03:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6CBE3FD9-04A3-40B7-A839-DAA534B7FD6D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srk60b04_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F7E07D1-C2EE-4BDD-B195-6CE22D35D3D0",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srk60b04:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1B3DD8F7-E860-4B21-B03B-0C4136C3D845"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srk60b05_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F9CE8BB-DEFA-40DA-B3D9-893BC5A7D23C",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srk60b05:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F86F7524-4456-48A0-9591-4A17555B990A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:srk60b06_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "042F981E-0484-45BF-A935-F6B0382C2522",
"versionEndExcluding": "2.5.2.104"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:srk60b06:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B906DFC5-058F-4C31-B92F-49393B15497B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}