AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-35782

HIGH · CVSS 8.1 EPSS 1.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-30 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It may be remotely exploitable.

CVE
CVE-2020-35782
Severity
HIGH
CVSS
8.1
EPSS
1.64%

Original NVD Description

Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)