First published: Tue Apr 28 2020(Updated: )
Certain NETGEAR devices are affected by reflected XSS. This affects JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.20, R6050 before 1.0.1.10, R6220 before 1.1.0.60, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.46, WNR2020 before 1.1.0.46, and WNR2050 before 1.1.0.46.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Jnr1010 Firmware | <1.1.0.46 | |
NETGEAR JNR1010 | =v2 | |
Netgear Jr6150 Firmware | <1.0.1.10 | |
Netgear Jr6150 | ||
Netgear Jwnr2010 Firmware | <1.1.0.46 | |
Netgear Jwnr2010 | =v5 | |
Netgear Pr2000 Firmware | <1.0.0.20 | |
Netgear Pr2000 | ||
Netgear R6050 Firmware | <1.0.1.10 | |
Netgear R6050 | ||
Netgear R6220 Firmware | <1.1.0.60 | |
NETGEAR R6220 | ||
Netgear Wndr3700 Firmware | <1.1.0.50 | |
Netgear WNDR3700 | =v5 | |
Netgear Wnr1000 Firmware | <1.1.0.46 | |
Netgear WNR1000 | =v4 | |
Netgear Wnr2020 Firmware | <1.1.0.46 | |
Netgear Wnr2020 | ||
Netgear Wnr2050 Firmware | <1.1.0.46 | |
Netgear Wnr2050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-21209 is medium (4.8).
NETGEAR devices affected by CVE-2018-21209 include JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.20, R6050 before 1.0.1.10, R6220 before 1.1.0.60, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.46, WNR2020 before 1.1.0.46, and WNR2050 before 1.1.0.46.
CVE-2018-21209 affects NETGEAR JNR1010v2 before 1.1.0.46.
To fix CVE-2018-21209 on your NETGEAR device, you should update the firmware to a version beyond the vulnerable range.
You can find more information about CVE-2018-21209 at the following reference: https://kb.netgear.com/000055140/Security-Advisory-for-Reflected-Cross-Site-Scripting-on-Some-Routers-and-Extenders-PSV-2017-2514