CVE-2018-21164

HIGH

NETGEAR R6220 and WNDR3700v5 Firmware < 1.1.0.64 and < 1.1.0.54 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.

Scores

CVSS v3 7.2
EPSS 0.0106
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
netgear/r6220_firmware < 1.1.0.64
netgear/wndr3700_firmware < 1.1.0.54
Published Apr 23, 2020
Tracked Since Feb 18, 2026