First published: Tue Apr 28 2020(Updated: )
Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Jnr1010 Firmware | <1.1.0.48 | |
NETGEAR JNR1010 | =v2 | |
Netgear Jwnr2010 Firmware | <1.1.0.48 | |
Netgear Jwnr2010 | =v5 | |
Netgear Wnr1000 Firmware | <1.1.0.48 | |
Netgear WNR1000 | =v4 | |
Netgear Wnr2020 Firmware | <1.1.0.48 | |
Netgear Wnr2020 | ||
Netgear Wnr2050 Firmware | <1.1.0.48 | |
Netgear Wnr2050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21226 is a vulnerability that affects certain NETGEAR devices, allowing an attacker to bypass authentication.
CVE-2018-21226 affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.
The severity of CVE-2018-21226 is rated as high with a CVSS score of 8.8.
An attacker can exploit CVE-2018-21226 by bypassing authentication on vulnerable NETGEAR devices.
Yes, NETGEAR has released firmware updates to address the authentication bypass vulnerability. Please refer to the official NETGEAR advisory for more information.