Vulnerability record · CVE-2020-26919 · published 9 October 2020
CVE-2020-26919: NETGEAR JGS516PE switch missing function-level access control
Netgear · Jgs516pe Firmware
NETGEAR JGS516PE devices before firmware 2.6.0.43 lack access control at the function level, allowing protected management functions to be invoked without proper authorization. The flaw carries a critical CVSS score of 9.8 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it matters for any organization still running these switches.
Description
NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, plus KEV listing and very high EPSS, makes this an urgent patch-or-isolate case.
What it is
NETGEAR JGS516PE devices before firmware 2.6.0.43 lack access control at the function level, allowing protected management functions to be invoked without proper authorization. The flaw carries a critical CVSS score of 9.8 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it matters for any organization still running these switches.
Impact
An unauthenticated remote attacker can reach management functions that should require authorization, gaining high impact to confidentiality, integrity and availability of the device. That can mean full control over switch configuration and traffic handling.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction required, so the management interface is exposed to anyone who can route to it. No authentication is needed per the vector and the missing-access-control description.
Exploitation
CVE-2020-26919 is in CISA's KEV catalog with a 2021-11-03 addition date, indicating known exploitation, and EPSS shows a 30-day probability of 0.57195 (99th percentile). No ransomware campaign use is recorded.
What to do
- Upgrade JGS516PE firmware to 2.6.0.43 or later per the NETGEAR advisory.
- If patching is not immediately possible, remove the switch management interface from untrusted networks and restrict it to a dedicated management VLAN.
- Block or filter access to the device's web/management ports at network boundaries and from user segments.
- Replace end-of-support units that cannot receive the fixed firmware.
- Review switch configurations for unauthorized changes after exposure.
Detection
- Monitor network logs for unexpected access to the JGS516PE management interface from non-management hosts.
- Alert on configuration changes or reboots on JGS516PE devices outside change windows.
- Hunt for scanning or requests targeting the switch management ports from internal or external sources.
- Audit firmware versions across JGS516PE inventory to find units below 2.6.0.43.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-26919 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-26919 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-26919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.