CVE-2018-21209: XSS
Certain NETGEAR devices are affected by reflected XSS. This affects JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.20, R6050 before 1.0.1.10, R6220 before 1.1.0.60, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.46, WNR2020 before 1.1.0.46, and WNR2050 before 1.1.0.46.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-21209?
The severity of CVE-2018-21209 is medium (4.8).
Which NETGEAR devices are affected by CVE-2018-21209?
NETGEAR devices affected by CVE-2018-21209 include JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.20, R6050 before 1.0.1.10, R6220 before 1.1.0.60, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.46, WNR2020 before 1.1.0.46, and WNR2050 before 1.1.0.46.
How does CVE-2018-21209 affect NETGEAR JNR1010v2?
CVE-2018-21209 affects NETGEAR JNR1010v2 before 1.1.0.46.
How do I fix CVE-2018-21209 on my NETGEAR device?
To fix CVE-2018-21209 on your NETGEAR device, you should update the firmware to a version beyond the vulnerable range.
Where can I find more information about CVE-2018-21209?
You can find more information about CVE-2018-21209 at the following reference: https://kb.netgear.com/000055140/Security-Advisory-for-Reflected-Cross-Site-Scripting-on-Some-Routers-and-Extenders-PSV-2017-2514