TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2018-21114

MEDIUM
6.8

Beschreibung

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, EX6150v2 before 1.0.1.70, EX6100v2 before 1.0.1.70, EX6200v2 before 1.0.1.64, EX7300 before 1.0.2.136, EX6400 before 1.0.2.136, R6100 before 1.0.1.16, R7500 before 1.0.0.110, R7800 before 1.0.2.32, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.56, WN3000RPv3 before 1.0.2.52, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.

CVE Details

CVSS v3.1 Bewertung6.8
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorADJACENT_NETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht4/22/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

netgear:d7800netgear:d7800_firmwarenetgear:ex6100netgear:ex6100_firmwarenetgear:ex6150netgear:ex6150_firmwarenetgear:ex6200netgear:ex6200_firmwarenetgear:ex6400netgear:ex6400_firmwarenetgear:ex7300netgear:ex7300_firmwarenetgear:r6100netgear:r6100_firmwarenetgear:r7500netgear:r7500_firmwarenetgear:r7800netgear:r7800_firmwarenetgear:r9000netgear:r9000_firmwarenetgear:wn3000rpnetgear:wn3000rp_firmwarenetgear:wndr4300netgear:wndr4300_firmwarenetgear:wndr4500netgear:wndr4500_firmware

Schwachen (CWE)

CWE-74

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.