First published: Mon Apr 27 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, and R7800 before 1.0.2.42.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear D7800 Firmware | <1.0.1.34 | |
Netgear D7800 | ||
Netgear Dm200 Firmware | <1.0.0.50 | |
Netgear Dm200 | ||
Netgear R6100 Firmware | <1.0.1.22 | |
Netgear R6100 | ||
Netgear R7500 Firmware | <1.0.0.122 | |
Netgear R7500 | ||
Netgear R7500 Firmware | <1.0.3.26 | |
Netgear R7500 | =v2 | |
NETGEAR R7800 firmware | <1.0.2.42 | |
NETGEAR R7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21154 is a vulnerability that allows command injection by an authenticated user in certain NETGEAR devices.
CVE-2018-21154 affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, and R7800 before 1.0.2.42.
The severity of CVE-2018-21154 is medium with a CVSS score of 6.8.
To fix CVE-2018-21154, you should update the firmware of the affected NETGEAR devices to the latest version.
You can find more information about CVE-2018-21154 on the NETGEAR security advisory page: [https://kb.netgear.com/000059479/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Gateways-and-Routers-PSV-2017-3133](https://kb.netgear.com/000059479/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Gateways-and-Routers-PSV-2017-3133)