CVE-2018-21225
6.8
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, D7800 before 1.0.1.34, D8500 before 1.0.3.39, R6700 before 1.0.1.30, R6700v2 before 1.2.0.16, R6800 before 1.2.0.16, R6900 before 1.0.1.30, R6900P before 1.2.0.22, R6900v2 before 1.2.0.16, R7000 before 1.0.9.12, R7000P before 1.2.0.22, R7500v2 before 1.0.3.20, R7800 before 1.0.2.44, R8300 before 1.0.2.106, R8500 before 1.0.2.106, and R9000 before 1.0.2.52.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.34 |
| Running on/with | Platform Versions |
|---|---|
Netgear D7800 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.60 |
| Running on/with | Platform Versions |
|---|---|
Netgear D7000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.3.39 |
| Running on/with | Platform Versions |
|---|---|
Netgear D8500 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.30 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6700 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0.16 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6700 | Version v2 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0.16 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6800 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.30 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6900 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0.16 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6900 | Version v2 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0.22 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6900p | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.9.12 |
| Running on/with | Platform Versions |
|---|---|
Netgear R7000 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0.22 |
| Running on/with | Platform Versions |
|---|---|
Netgear R7000p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.3.20 |
| Running on/with | Platform Versions |
|---|---|
Netgear R7500 | Version v2 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.2.44 |
| Running on/with | Platform Versions |
|---|---|
Netgear R7800 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.2.106 |
| Running on/with | Platform Versions |
|---|---|
Netgear R8300 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.2.106 |
| Running on/with | Platform Versions |
|---|---|
Netgear R8500 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.2.52 |
| Running on/with | Platform Versions |
|---|---|
Netgear R9000 | All versions |
References (2)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.