CVE-2021-45673

MEDIUM WAF: High
CVSS 5.4 Published: 2021-12-26
CWE-79

Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P before 1.3.3.140, and RAX75 before 1.0.3.106.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
netgearr7000_firmwareup to 1.0.11.110
netgearr7900_firmwareup to 1.0.4.30
netgearr8000_firmwareup to 1.0.4.62
netgearrax200_firmwareup to 1.0.3.106
netgearr7000p_firmwareup to 1.3.3.140
netgearrax80_firmwareup to 1.0.3.106
netgearr6900p_firmwareup to 1.3.3.140
netgearrax75_firmwareup to 1.0.3.106

References

Back to CVE Database