← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-21162

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6250 before 1.0.4.8, R6300v2 before 1.0.4.6, R6400 before 1.0.1.12, R6700 before 1.0.1.16, R7000 before 1.0.7.10, R7100LG before 1.0.0.42, R7300DST before 1.0.0.44, R7900 before 1.0.1.12, R8000 before 1.0.3.36, R8300 before 1.0.2.74, R8500 before 1.0.2.74, WNDR3400v3 before 1.0.1.14, and WNR3500Lv2 before 1.2.0.48.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:3.35%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
netgear d6400_firmware all
netgear d6400 all
netgear ex6200_firmware all
netgear ex6200 all
netgear ex7000_firmware all
netgear ex7000 all
netgear r6250_firmware all
netgear r6250 all
netgear r6300_firmware all
netgear r6300 v2
netgear r6400_firmware all
netgear r6400 all
netgear r6700_firmware all
netgear r6700 all
netgear r7000_firmware all
netgear r7000 all
netgear r7100lg_firmware all
netgear r7100lg all
netgear r7300dst_firmware all
netgear r7300dst all
netgear r7900_firmware all
netgear r7900 all
netgear r8000_firmware all
netgear r8000 all
netgear r8300_firmware all
netgear r8300 all
netgear r8500_firmware all
netgear r8500 all
netgear wndr3400_firmware all
netgear wndr3400 v3
netgear wnr3500l_firmware all
netgear wnr3500l v2

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.353%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-04-20T00:00:00
Published2020-04-23T20:16:47
Patch Date2018-06-14
Last Updated2024-08-05T12:26:38

LINK COPIED TO CLIPBOARD