First published: Sun Dec 26 2021(Updated: )
Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6900p Firmware | <1.3.3.140 | |
Netgear R6900P | ||
Netgear R7000p Firmware | <1.3.3.140 | |
Netgear R7000P | ||
Netgear R7900p Firmware | <1.4.2.84 | |
Netgear R7900p | ||
Netgear R7960p Firmware | <1.4.2.84 | |
Netgear R7960p | ||
Netgear R8000p Firmware | <1.4.2.84 | |
Netgear R8000p | ||
Netgear Rax75 Firmware | <1.0.3.106 | |
Netgear Rax75 | ||
Netgear Rax80 Firmware | <1.0.3.106 | |
Netgear Rax80 | ||
All of | ||
Netgear R6900p Firmware | <1.3.3.140 | |
Netgear R6900P | ||
All of | ||
Netgear R7000p Firmware | <1.3.3.140 | |
Netgear R7000P | ||
All of | ||
Netgear R7900p Firmware | <1.4.2.84 | |
Netgear R7900p | ||
All of | ||
Netgear R7960p Firmware | <1.4.2.84 | |
Netgear R7960p | ||
All of | ||
Netgear R8000p Firmware | <1.4.2.84 | |
Netgear R8000p | ||
All of | ||
Netgear Rax75 Firmware | <1.0.3.106 | |
Netgear Rax75 | ||
All of | ||
Netgear Rax80 Firmware | <1.0.3.106 | |
Netgear Rax80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.
The severity level of CVE-2021-45499 is high (8.8).
To fix the authentication bypass vulnerability, upgrade your NETGEAR device firmware to version 1.3.3.140 or higher for R6900P and R7000P, version 1.4.2.84 or higher for R7900P, R7960P, and R8000P, and version 1.0.3.106 or higher for RAX75 and RAX80.
You can find more information about the authentication bypass vulnerability in NETGEAR devices in the security advisory [link].
Netgear R6900P devices with firmware version 1.3.3.140 and below are vulnerable to the authentication bypass vulnerability.