CVE-2018-21096
7.4
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 5.9
Source: NVD
Description
Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7, WND930 before 2.1.5, and WN604 before 3.3.10.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wac120 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.5.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wac505 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.5.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wac510 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.7.11.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wnap320 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.7.11.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wnap210 | Version v2 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.7.11.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap350 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.7.11.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap360 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.7.11.4 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap660 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap620 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wnd930 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.10 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wn604 | All versions |
References (2)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.