Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-45674


Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.


Published

2021-12-26T01:15:21.193

Last Modified

2024-11-21T06:32:51.063

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.2 (LOW)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear r7000_firmware < 1.0.11.110 Yes
Hardware netgear r7000 - No
Operating System netgear r7900_firmware < 1.0.4.30 Yes
Hardware netgear r7900 - No
Operating System netgear r8000_firmware < 1.0.4.62 Yes
Hardware netgear r8000 - No
Operating System netgear rax15_firmware < 1.0.2.82 Yes
Hardware netgear rax15 - No
Operating System netgear rax20_firmware < 1.0.2.82 Yes
Hardware netgear rax20 - No
Operating System netgear rax200_firmware < 1.0.3.106 Yes
Hardware netgear rax200 - No
Operating System netgear rax75_firmware < 1.0.3.106 Yes
Hardware netgear rax75 - No
Operating System netgear rax80_firmware < 1.0.3.106 Yes
Hardware netgear rax80 - No

References