ZeroHour

CVE-2020-26919

KEVlarge1

Missing Function-Level Access Control in NETGEAR JGS516PE Smart Managed Switches

CISA: Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
57%p99
Published
()
KEV added
AI analysis

CVE-2020-26919 is a missing function-level access control flaw in NETGEAR JGS516PE ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switches running firmware before 2.6.0.43. An unauthenticated remote attacker can invoke privileged switch functions over the network without authorization, consistent with the CVSS 9.8 critical score (network vector, no privileges or user interaction required). Successful exploitation grants the attacker full functional control of the switch's management functions, with high impact on confidentiality, integrity, and availability of the device. Any organization or site running a JGS516PE switch on affected firmware is exposed, particularly where the management interface is reachable from untrusted networks. The flaw is listed in the CISA Known Exploited Vulnerability Catalog (added 2021-11-03), indicating it is known to be exploited in the wild, and related reporting on Mirai variants targeting network devices suggests active scanning and botnet interest in this class of equipment.

What to do: Upgrade JGS516PE switch firmware to version 2.6.0.43 or later per NETGEAR's instructions, as required by the CISA KEV listing. Restrict the switch's management interface (web and network management protocols) to trusted management VLANs or administrative networks and avoid internet exposure. Check whether the device appears in KEV-driven scanning activity and monitor for Mirai-style botnet targeting of network infrastructure.

Affected
NETGEAR JGS516PE firmware (ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switch)All firmware versions before 2.6.0.43
Estimated exposure
largeon the order of tens of thousands of deployed JGS516PE switches, with a likely lower but non-trivial subset (thousands to tens of thousands) having management… — The JGS516PE is a long-selling small-business managed PoE+ switch with a substantial installed base, so exposure is estimated from typical SMB deployment patterns and the subset of such switches whose management interfaces are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

CISA Known Exploited Vulnerability
Affected
NETGEAR JGS516PE Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
netgear
Products
jgs516pe firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

New Mirai Variant Targeting Network Security Devices

New Mirai botnet variant exploits nine vulnerabilities in SonicWall, D-Link, Netgear, and other devices, with attacks ongoing at publication.

Unit 42 observed attacks exploiting VisualDoor (SonicWall SSL-VPN), CVE-2020-25506 (D-Link DNS-320), CVE-2020-26919 (Netgear ProSAFE Plus), and other flaws, with infrastructure rotating across at least three IP addresses between February 16 and March 13, 2021. Payloads were updated hours after CVE-2021-27561 and CVE-2021-27562 (Yealink Device Management, unauthenticated root RCE) and later added CVE-2021-22502 (Micro Focus Operation Bridge Reporter) and CVE-2019-19356 (Netis WF2419). Successful exploitation invokes wget to fetch shell scripts that download Mirai binaries compiled for multiple architectures and brute-forcers, and attacks were still ongoing when reported.

Palo Alto Unit 42 · 27d agoExploit / PoC in the wildCVE-2020-25506CVE-2020-26919CVE-2019-19356+3 CVEs