CVE-2021-45671: XSS
Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.62, EX7500 before 1.0.0.72, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.4.120, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.4.120, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.4.120, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-45671.
Which devices are affected by this vulnerability?
Certain NETGEAR devices are affected, including CBR40, EAX80, EX7500, R7900, R8000, RAX200, RBS40V, RBW30, MR60, RAX20, RAX45, RAX80, MS60, RAX15, RAX50, RAX75, RBR750, RBR850, RBS750, RBS850, RBK752, and RBK852.
What is the severity of CVE-2021-45671?
The severity of CVE-2021-45671 is medium with a CVSS score of 4.8.
How does this vulnerability impact affected devices?
This vulnerability allows for stored cross-site scripting (XSS) attacks, which can lead to unauthorized access, data theft, and potential compromise of the affected devices.
How can I fix CVE-2021-45671?
To fix CVE-2021-45671, Netgear has released firmware updates for the affected devices. Please refer to the Netgear security advisory for specific instructions and download links.