CVE-2018-21095

MEDIUM

NETGEAR SRR60 and SRS60 < 2.2.1.210 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by stored XSS. This affects SRR60 before 2.2.1.210 and SRS60 before 2.2.1.210.

Scores

CVSS v3 4.3
EPSS 0.0007
EPSS Percentile 20.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
netgear/srr60_firmware < 2.2.1.210
netgear/srs60_firmware < 2.2.1.210
Published Apr 27, 2020
Tracked Since Feb 18, 2026