First published: Thu Apr 23 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6220 Firmware | <1.1.0.64 | |
NETGEAR R6220 | ||
Netgear Wndr3700 Firmware | <1.1.0.54 | |
Netgear WNDR3700 | =v5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21164 is a vulnerability that allows an authenticated user to execute arbitrary commands on certain NETGEAR devices.
CVE-2018-21164 affects Netgear R6220 before version 1.1.0.64 and WNDR3700v5 before version 1.1.0.54.
CVE-2018-21164 has a severity rating of 7.2 (high).
To fix CVE-2018-21164, update your Netgear R6220 firmware to version 1.1.0.64 or later and update your WNDR3700v5 firmware to version 1.1.0.54 or later.
More information about CVE-2018-21164 can be found in the Netgear Security Advisory: https://kb.netgear.com/000055195/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2017-3171