CVE-2018-21164: OS Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-21164?
CVE-2018-21164 is a vulnerability that allows an authenticated user to execute arbitrary commands on certain NETGEAR devices.
Which devices are affected by CVE-2018-21164?
CVE-2018-21164 affects Netgear R6220 before version 1.1.0.64 and WNDR3700v5 before version 1.1.0.54.
How severe is CVE-2018-21164?
CVE-2018-21164 has a severity rating of 7.2 (high).
How can I fix CVE-2018-21164?
To fix CVE-2018-21164, update your Netgear R6220 firmware to version 1.1.0.64 or later and update your WNDR3700v5 firmware to version 1.1.0.54 or later.
Where can I find more information about CVE-2018-21164?
More information about CVE-2018-21164 can be found in the Netgear Security Advisory: https://kb.netgear.com/000055195/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2017-3171