CVE-2021-45668: XSS
Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX45 before 1.0.2.72, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this stored XSS vulnerability?
The vulnerability ID for this stored XSS vulnerability is CVE-2021-45668.
Which NETGEAR devices are affected by this stored XSS vulnerability?
This stored XSS vulnerability affects certain NETGEAR devices, including EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, R7900P before 1.4.1.66, and R8000P before 1.4.1.66.
What is the severity of vulnerability CVE-2021-45668?
The severity of vulnerability CVE-2021-45668 is medium with a CVSS score of 4.8.
How can I fix vulnerability CVE-2021-45668?
To fix vulnerability CVE-2021-45668, it is recommended to update the firmware of the affected NETGEAR devices to the latest version provided by the manufacturer.
Where can I find more information about this stored XSS vulnerability?
You can find more information about this stored XSS vulnerability in the Netgear Security Advisory PSV-2020-0257: [Netgear Security Advisory](https://kb.netgear.com/000064122/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Routers-and-Extenders-PSV-2020-0257)