CVE-2021-45499

HIGH

NETGEAR R6900P/R7000P/R7900P/R7960P/R8000P/RAX75/RAX80 Firmware - Unauthenticated Authentication Bypass

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.

References (1)

Core 1

Scores

CVSS v3 8.2
EPSS 0.0051
EPSS Percentile 66.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Details

Status published
Products (7)
netgear/r6900p_firmware < 1.3.3.140
netgear/r7000p_firmware < 1.3.3.140
netgear/r7900p_firmware < 1.4.2.84
netgear/r7960p_firmware < 1.4.2.84
netgear/r8000p_firmware < 1.4.2.84
netgear/rax75_firmware < 1.0.3.106
netgear/rax80_firmware < 1.0.3.106
Published Dec 26, 2021
Tracked Since Feb 18, 2026