CVE-2018-21228
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, EX6100v2 before 1.0.1.50, EX6150v2 before 1.0.1.50, EX6200v2 before 1.0.1.44, EX6400 before 1.0.1.60, EX7300 before 1.0.1.60, R6100 before 1.0.1.16, R7500 before 1.0.0.110, R7800 before 1.0.2.32, R9000 before 1.0.2.30, WN3000RPv3 before 1.0.2.50, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.
Published:Apr 24, 2020
Last Modified:Nov 21, 2024
EPS:Apr 24, 2020
EPSS Score:0.00136
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Netgear
Product
D7800
Netgear
D7800
Vendor
Netgear
Product
D7800 Firmware
Netgear
D7800 Firmware
Vendor
Netgear
Product
Ex6100
Netgear
Ex6100
Vendor
Netgear
Product
Ex6100 Firmware
Netgear
Ex6100 Firmware
Vendor
Netgear
Product
Ex6150
Netgear
Ex6150
Vendor
Netgear
Product
Ex6150 Firmware
Netgear
Ex6150 Firmware
Vendor
Netgear
Product
Ex6200
Netgear
Ex6200
Vendor
Netgear
Product
Ex6200 Firmware
Netgear
Ex6200 Firmware
Vendor
Netgear
Product
Ex6400
Netgear
Ex6400
Vendor
Netgear
Product
Ex6400 Firmware
Netgear
Ex6400 Firmware
Vendor
Netgear
Product
Ex7300
Netgear
Ex7300
Vendor
Netgear
Product
Ex7300 Firmware
Netgear
Ex7300 Firmware
Vendor
Netgear
Product
R6100
Netgear
R6100
Vendor
Netgear
Product
R6100 Firmware
Netgear
R6100 Firmware
Vendor
Netgear
Product
R7500
Netgear
R7500
Vendor
Netgear
Product
R7500 Firmware
Netgear
R7500 Firmware
Vendor
Netgear
Product
R7800
Netgear
R7800
Vendor
Netgear
Product
R7800 Firmware
Netgear
R7800 Firmware
Vendor
Netgear
Product
R9000
Netgear
R9000
Vendor
Netgear
Product
R9000 Firmware
Netgear
R9000 Firmware
Vendor
Netgear
Product
Wn3000rp
Netgear
Wn3000rp
Vendor
Netgear
Product
Wn3000rp Firmware
Netgear
Wn3000rp Firmware
Vendor
Netgear
Product
Wndr4300
Netgear
Wndr4300
Vendor
Netgear
Product
Wndr4300 Firmware
Netgear
Wndr4300 Firmware
Vendor
Netgear
Product
Wndr4500
Netgear
Wndr4500
Vendor
Netgear
Product
Wndr4500 Firmware
Netgear
Wndr4500 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
