CVE-2018-21167: XSS
Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.57, DM200 before 1.0.0.50, EX2700 before 1.0.1.32, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.70, EX6200v2 before 1.0.1.62, EX6400 before 1.0.1.78, EX7300 before 1.0.1.78, EX8000 before 1.0.0.114, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WN2000RPTv3 before 1.0.1.26, WN3000RPv3 before 1.0.2.66, WN3100RPv2 before 1.0.0.42, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by stored XSS?
The affected NETGEAR devices are D6100, DM200, EX2700, EX6100v2, EX6150v2, EX6200v2, EX6400, EX7300, EX8000, R6100, R7800, R8900, R9000, Wn2000rpt, Wn3000rp, Wn3100rp, Wndr3700, Wndr4300, Wndr4500, and Wnr2000.
What is the severity rating of CVE-2018-21167?
The severity rating of CVE-2018-21167 is medium with a CVSS score of 5.5.
How can I fix the stored XSS vulnerability on my NETGEAR device?
You can fix the stored XSS vulnerability on your NETGEAR device by updating to the latest firmware version provided by NETGEAR.
Where can I find more information about CVE-2018-21167?
You can find more information about CVE-2018-21167 on the NETGEAR knowledge base at the following link: [https://kb.netgear.com/000055191/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Routers-Gateways-Extenders-and-DSL-Modems-PSV-2017-3093]
What is the CWE ID of CVE-2018-21167?
The CWE ID of CVE-2018-21167 is 79.