PT-2021-22194 · NetGear · Netgear R7200+17
Nstarke
·
Published
2021-08-10
·
Updated
2021-08-19
·
CVE-2021-38537
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NETGEAR D6200 versions 1.1.00.39 and earlier
NETGEAR D7000 versions 1.0.1.77 and earlier
NETGEAR R6020 versions 1.0.0.47 and earlier
NETGEAR R6080 versions 1.0.0.47 and earlier
NETGEAR R6120 versions 1.0.0.65 and earlier
NETGEAR R6260 versions 1.1.0.77 and earlier
NETGEAR R6700v2 versions 1.2.0.75 and earlier
NETGEAR R6800 versions 1.2.0.75 and earlier
NETGEAR R6900v2 versions 1.2.0.75 and earlier
NETGEAR R6850 versions 1.1.0.77 and earlier
NETGEAR R7200 versions 1.2.0.75 and earlier
NETGEAR R7350 versions 1.2.0.75 and earlier
NETGEAR R7400 versions 1.2.0.75 and earlier
NETGEAR R7450 versions 1.2.0.75 and earlier
NETGEAR AC2100 versions 1.2.0.75 and earlier
NETGEAR AC2400 versions 1.2.0.75 and earlier
NETGEAR AC2600 versions 1.2.0.75 and earlier
NETGEAR RAX40 versions 1.0.3.61 and earlier
Description
The issue is related to stored XSS, which affects certain NETGEAR devices.
Recommendations
For NETGEAR D6200 version 1.1.00.39 and earlier, update to version 1.1.00.40 or later.
For NETGEAR D7000 version 1.0.1.77 and earlier, update to version 1.0.1.78 or later.
For NETGEAR R6020 version 1.0.0.47 and earlier, update to version 1.0.0.48 or later.
For NETGEAR R6080 version 1.0.0.47 and earlier, update to version 1.0.0.48 or later.
For NETGEAR R6120 version 1.0.0.65 and earlier, update to version 1.0.0.66 or later.
For NETGEAR R6260 version 1.1.0.77 and earlier, update to version 1.1.0.78 or later.
For NETGEAR R6700v2 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR R6800 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR R6900v2 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR R6850 version 1.1.0.77 and earlier, update to version 1.1.0.78 or later.
For NETGEAR R7200 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR R7350 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR R7400 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR R7450 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR AC2100 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR AC2400 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR AC2600 version 1.2.0.75 and earlier, update to version 1.2.0.76 or later.
For NETGEAR RAX40 version 1.0.3.61 and earlier, update to version 1.0.3.62 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Ac2100
Netgear Ac2400
Netgear Ac2600
Netgear D6200
Netgear R7000
Netgear R6020
Netgear R6080
Netgear R6120
Netgear R6260
Netgear R6700V2
Netgear R6800
Netgear R6850
Netgear R6900V2
Netgear R7200
Netgear R7350
Netgear R7400
Netgear R7450
Netgear Rax40