CVE-2021-45499
HIGHNETGEAR R6900P/R7000P/R7900P/R7960P/R8000P/RAX75/RAX80 Firmware - Unauthenticated Authentication Bypass
Title source: llmDescription
Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://kb.netgear.com/000064445/Security-Advisory-for-Authentication-Bypass-on-Some-Routers-PSV-2019-0027
Scores
CVSS v3
8.2
EPSS
0.0051
EPSS Percentile
66.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Details
Status
published
Products (7)
netgear/r6900p_firmware
< 1.3.3.140
netgear/r7000p_firmware
< 1.3.3.140
netgear/r7900p_firmware
< 1.4.2.84
netgear/r7960p_firmware
< 1.4.2.84
netgear/r8000p_firmware
< 1.4.2.84
netgear/rax75_firmware
< 1.0.3.106
netgear/rax80_firmware
< 1.0.3.106
Published
Dec 26, 2021
Tracked Since
Feb 18, 2026