CVE-2018-21114: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, EX6150v2 before 1.0.1.70, EX6100v2 before 1.0.1.70, EX6200v2 before 1.0.1.64, EX7300 before 1.0.2.136, EX6400 before 1.0.2.136, R6100 before 1.0.1.16, R7500 before 1.0.0.110, R7800 before 1.0.2.32, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.56, WN3000RPv3 before 1.0.2.52, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2018-21114?
D7800 before 1.0.1.44, EX6150v2 before 1.0.1.70, EX6100v2 before 1.0.1.70, EX6200v2 before 1.0.1.64, EX7300 before 1.0.2.136, EX6400 before 1.0.2.136, R6100 before 1.0.1.16, R7500 before 1.0.0.110, R7800 before 1.0.2.32.
What is the severity of CVE-2018-21114?
Medium, with a severity value of 6.8.
How can I fix CVE-2018-21114?
Update the firmware of the affected NETGEAR devices to the patched versions.
Where can I find more information about CVE-2018-21114?
You can find more information about CVE-2018-21114 in the Netgear Security Advisory PSV-2017-0645.
What are the Common Weakness Enumerations (CWE) associated with CVE-2018-21114?
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') and CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection').