CVE-2018-21123

HIGH

NETGEAR WC7500 WC7520 WC7600 < 6.5.3.9 - Unauthenticated OS Command Injection

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9.

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 68.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (3)
netgear/wc7500_firmware < 6.5.3.9
netgear/wc7520_firmware < 6.5.3.9
netgear/wc7600_firmware < 6.5.3.9
Published Apr 22, 2020
Tracked Since Feb 18, 2026