PT-2021-6168 · NetGear · Ex6120+16

Published

2021-09-26

·

Updated

2022-01-06

·

CVE-2021-45668

CVSS v2.0

7.5

High

VectorAV:N/AC:M/Au:S/C:P/I:C/A:P
Name of the Vulnerable Software and Affected Versions EAX20 versions 1.0.0.0 through 1.0.0.47 EAX80 versions 1.0.0.0 through 1.0.1.63 EX3700 versions 1.0.0.0 through 1.0.0.89 EX3800 versions 1.0.0.0 through 1.0.0.89 EX6120 versions 1.0.0.0 through 1.0.0.63 EX6130 versions 1.0.0.0 through 1.0.0.43 EX7500 versions 1.0.0.0 through 1.0.0.71 R7960P versions 1.4.1.0 through 1.4.1.65 R7900P versions 1.4.1.0 through 1.4.1.65 R8000P versions 1.4.1.0 through 1.4.1.65 RAX15 versions 1.0.0.0 through 1.0.2.81 RAX20 versions 1.0.0.0 through 1.0.2.81 RAX200 versions 1.0.0.0 through 1.0.3.105 RAX45 versions 1.0.0.0 through 1.0.2.71 RAX50 versions 1.0.0.0 through 1.0.2.71 RAX75 versions 1.0.0.0 through 1.0.3.105 RAX80 versions 1.0.0.0 through 1.0.3.105
Description The issue is related to stored XSS in certain NETGEAR devices. This occurs due to a lack of protection for the web page structure, allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For EAX20 versions 1.0.0.0 through 1.0.0.47, update to version 1.0.0.48 or later. For EAX80 versions 1.0.0.0 through 1.0.1.63, update to version 1.0.1.64 or later. For EX3700 versions 1.0.0.0 through 1.0.0.89, update to version 1.0.0.90 or later. For EX3800 versions 1.0.0.0 through 1.0.0.89, update to version 1.0.0.90 or later. For EX6120 versions 1.0.0.0 through 1.0.0.63, update to version 1.0.0.64 or later. For EX6130 versions 1.0.0.0 through 1.0.0.43, update to version 1.0.0.44 or later. For EX7500 versions 1.0.0.0 through 1.0.0.71, update to version 1.0.0.72 or later. For R7960P versions 1.4.1.0 through 1.4.1.65, update to version 1.4.1.66 or later. For R7900P versions 1.4.1.0 through 1.4.1.65, update to version 1.4.1.66 or later. For R8000P versions 1.4.1.0 through 1.4.1.65, update to version 1.4.1.66 or later. For RAX15 versions 1.0.0.0 through 1.0.2.81, update to version 1.0.2.82 or later. For RAX20 versions 1.0.0.0 through 1.0.2.81, update to version 1.0.2.82 or later. For RAX200 versions 1.0.0.0 through 1.0.3.105, update to version 1.0.3.106 or later. For RAX45 versions 1.0.0.0 through 1.0.2.71, update to version 1.0.2.72 or later. For RAX50 versions 1.0.0.0 through 1.0.2.71, update to version 1.0.2.72 or later. For RAX75 versions 1.0.0.0 through 1.0.3.105, update to version 1.0.3.106 or later. For RAX80 versions 1.0.0.0 through 1.0.3.105, update to version 1.0.3.106 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01084
CVE-2021-45668

Affected Products

Eax20
Eax80
Ex3700
Ex3800
Ex6120
Ex6130
Ex7500
R7900P
R7960P
R8000P
Rax15
Rax20
Rax200
Rax45
Rax50
Rax75
Rax80