PT-2021-5902 · NetGear · Netgear R7000

Published

2021-09-26

·

Updated

2022-01-05

·

CVE-2021-45664

CVSS v3.1

5.6

Medium

VectorAC:L/AV:P/A:N/C:H/I:L/PR:H/S:C/UI:R
Name of the Vulnerable Software and Affected Versions NETGEAR R7000 versions prior to 1.0.11.126
Description The issue is related to a stored XSS problem, where the vulnerability in the NETGEAR R7000 Wi-Fi router's embedded software is connected to the lack of protection for the web page structure. This could allow an attacker to perform cross-site scripting attacks.
Recommendations For versions prior to 1.0.11.126, update to version 1.0.11.126 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface of the router until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00417
CVE-2021-45664

Affected Products

Netgear R7000