CVE-2018-21117: High severity netgear xr500 vulnerability
Published Apr 22, 2020
·Updated
NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers via the traceroute handler.
Affected Software
2 affected components
Netgear Xr500 Firmware<2.3.2.32
Netgear XR500
Event History
Apr 22, 2020
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2018-21117?
CVE-2018-21117 is classified as a critical vulnerability due to its ability to allow remote code execution by unauthenticated attackers.
2
How do I fix CVE-2018-21117?
To fix CVE-2018-21117, update the NETGEAR XR500 firmware to version 2.3.2.32 or later.
3
Who is affected by CVE-2018-21117?
CVE-2018-21117 affects all NETGEAR XR500 devices running firmware versions prior to 2.3.2.32.
4
What types of attacks can be executed through CVE-2018-21117?
CVE-2018-21117 allows remote code execution, enabling attackers to potentially take control of the affected device.
5
Is CVE-2018-21117 a pre-authentication vulnerability?
Yes, CVE-2018-21117 is a pre-authentication vulnerability, meaning it can be exploited without any authentication required.