Loading
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.
Use CWE-384, Netgear vendor hub and Gs116e Firmware product page to widen CVE-2020-35229 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-35231, CVE-2020-35223 and CVE-2020-35221 for nearby disclosures in the same product family.