CVE-2021-45673

MEDIUM

NETGEAR R7000/R7900/R8000/RAX200/R7000P/RAX80/R6900P/RAX75 Firmware - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P before 1.3.3.140, and RAX75 before 1.0.3.106.

References (1)

Core 1

Scores

CVSS v3 4.8
EPSS 0.0020
EPSS Percentile 41.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (8)
netgear/r6900p_firmware < 1.3.3.140
netgear/r7000_firmware < 1.0.11.110
netgear/r7000p_firmware < 1.3.3.140
netgear/r7900_firmware < 1.0.4.30
netgear/r8000_firmware < 1.0.4.62
netgear/rax200_firmware < 1.0.3.106
netgear/rax75_firmware < 1.0.3.106
netgear/rax80_firmware < 1.0.3.106
Published Dec 26, 2021
Tracked Since Feb 18, 2026