PT-2021-18069 · NetGear · Rax75+15

Published

2021-03-23

·

Updated

2021-03-24

·

CVE-2021-29080

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: NETGEAR RBK852 versions prior to 3.2.10.11 NETGEAR RBK853 versions prior to 3.2.10.11 NETGEAR RBR854 versions prior to 3.2.10.11 NETGEAR RBR850 versions prior to 3.2.10.11 NETGEAR RBS850 versions prior to 3.2.10.11 NETGEAR CBR40 versions prior to 2.5.0.10 NETGEAR R7000 versions prior to 1.0.11.116 NETGEAR R6900P versions prior to 1.3.2.126 NETGEAR R7900 versions prior to 1.0.4.38 NETGEAR R7960P versions prior to 1.4.1.66 NETGEAR R8000 versions prior to 1.0.4.66 NETGEAR R7900P versions prior to 1.4.1.66 NETGEAR R8000P versions prior to 1.4.1.66 NETGEAR RAX75 versions prior to 1.0.3.102 NETGEAR RAX80 versions prior to 1.0.3.102 NETGEAR R7000P versions prior to 1.3.2.126
Description: Certain NETGEAR devices are affected by a password reset issue that can be exploited by an unauthenticated attacker.
Recommendations: For RBK852 versions prior to 3.2.10.11, update to version 3.2.10.11 or later. For RBK853 versions prior to 3.2.10.11, update to version 3.2.10.11 or later. For RBR854 versions prior to 3.2.10.11, update to version 3.2.10.11 or later. For RBR850 versions prior to 3.2.10.11, update to version 3.2.10.11 or later. For RBS850 versions prior to 3.2.10.11, update to version 3.2.10.11 or later. For CBR40 versions prior to 2.5.0.10, update to version 2.5.0.10 or later. For R7000 versions prior to 1.0.11.116, update to version 1.0.11.116 or later. For R6900P versions prior to 1.3.2.126, update to version 1.3.2.126 or later. For R7900 versions prior to 1.0.4.38, update to version 1.0.4.38 or later. For R7960P versions prior to 1.4.1.66, update to version 1.4.1.66 or later. For R8000 versions prior to 1.0.4.66, update to version 1.0.4.66 or later. For R7900P versions prior to 1.4.1.66, update to version 1.4.1.66 or later. For R8000P versions prior to 1.4.1.66, update to version 1.4.1.66 or later. For RAX75 versions prior to 1.0.3.102, update to version 1.0.3.102 or later. For RAX80 versions prior to 1.0.3.102, update to version 1.0.3.102 or later. For R7000P versions prior to 1.3.2.126, update to version 1.3.2.126 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29080

Affected Products

Cbr40
R6900P
R7000
R7000P
R7900
R7900P
R7960P
R8000
R8000P
Rax75
Rax80
Rbk852
Rbk853
Rbr850
Rbr854
Rbs850