LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-26919: Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-26919 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Netgear JGS516PE devices contain a missing function level access control vulnerability.

CVE-2020-26919 is a missing function level access control vulnerability in NETGEAR JGS516PE devices. In plain terms, the device fails to properly enforce which users or sessions are allowed to invoke certain administrative or management functions. This matters because network switches of this class often sit at the edge or in access layers; if an attacker can reach the management interface, weak access control can let them perform actions reserved for privileged operators, potentially altering configuration, disrupting connectivity, or using the device as a foothold deeper into the network.

CISA summarizes the issue as a missing function level access control vulnerability on these devices and directs organizations to apply updates per vendor instructions. Specifics such as exact firmware ranges, attack prerequisites, and scoring must be confirmed against the vendor advisory.

How it works

Missing function level access control means the application or device firmware does not adequately check authorization before executing sensitive operations. An attacker who can authenticate at a lower privilege level—or in some cases reach an exposed management endpoint without proper checks—may be able to call functions intended only for administrators. For network switches, that class of flaw typically involves management-plane features such as configuration changes, account handling, or diagnostic actions.

Public detail on the precise abuse path for CVE-2020-26919 is limited. Defenders should assume that once an attacker has network reachability to the management interface and any required initial access, they may invoke restricted functions without the expected authorization gate. Do not rely on invented exploit steps; validate mechanics and preconditions in the NETGEAR advisory for this CVE.

Am I affected? How to find it in your systems

The affected product is the NETGEAR JGS516PE. These are managed Gigabit Ethernet switches commonly deployed in small-to-medium business, branch, or departmental networks for access-layer connectivity and basic PoE or management features.

How to remediate

Patch first. Apply the updates NETGEAR provides for the JGS516PE as instructed in the vendor advisory for CVE-2020-26919. CISA’s required action is to apply updates per vendor instructions; follow the vendor’s documented upgrade path, verify firmware integrity, and confirm the device reports the remediated version after reboot.

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

If your data may have been exposed

Actively exploited vulnerabilities on network infrastructure can lead to configuration compromise, credential theft, or lateral movement that ultimately exposes data elsewhere in the environment. Ransomware use associated with this CVE is not documented in the provided facts; still, investigate any switch that showed signs of unauthorized management activity. Review adjacent systems for follow-on access, rotate credentials that may have traversed the device, and check whether sensitive data stores were reachable from the affected segment. You can run a free exposure scan of your email addresses against known breach datasets to see whether your identities appear in prior documented breaches while you complete incident scoping.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNETGEAR · JGS516PE Devices
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities