CVE-2018-21114
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
22/04/2020
Last modified:
24/04/2020
Description
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, EX6150v2 before 1.0.1.70, EX6100v2 before 1.0.1.70, EX6200v2 before 1.0.1.64, EX7300 before 1.0.2.136, EX6400 before 1.0.2.136, R6100 before 1.0.1.16, R7500 before 1.0.0.110, R7800 before 1.0.2.32, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.56, WN3000RPv3 before 1.0.2.52, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Base Score 2.0
5.20
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* | 1.0.1.44 (excluding) | |
cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6150_firmware:*:*:*:*:*:*:*:* | 1.0.1.70 (excluding) | |
cpe:2.3:h:netgear:ex6150:v2:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6100_firmware:*:*:*:*:*:*:*:* | 1.0.1.70 (excluding) | |
cpe:2.3:h:netgear:ex6100:v2:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:* | 1.0.1.64 (excluding) | |
cpe:2.3:h:netgear:ex6200:v2:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex7300_firmware:*:*:*:*:*:*:*:* | 1.0.2.136 (excluding) | |
cpe:2.3:h:netgear:ex7300:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6400_firmware:*:*:*:*:*:*:*:* | 1.0.2.136 (excluding) | |
cpe:2.3:h:netgear:ex6400:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:r6100_firmware:*:*:*:*:*:*:*:* | 1.0.1.16 (excluding) | |
cpe:2.3:h:netgear:r6100:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:r7500_firmware:*:*:*:*:*:*:*:* | 1.0.0.110 (excluding) |
To consult the complete list of CPE names with products and versions, see this page