CVE-2021-45674: XSS
Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-45674?
The severity of CVE-2021-45674 is medium with a severity value of 4.8.
Which NETGEAR devices are affected by CVE-2021-45674?
NETGEAR devices R7000, R7900, R8000, RAX15, RAX20, RAX200, RAX75, and RAX80 are affected by CVE-2021-45674.
How does CVE-2021-45674 impact the affected NETGEAR devices?
CVE-2021-45674 allows for stored cross-site scripting (XSS) attacks on the affected NETGEAR devices.
What is the recommended firmware version to fix CVE-2021-45674?
To fix CVE-2021-45674, update the firmware of the affected NETGEAR devices to version 1.0.11.110 for R7000, 1.0.4.30 for R7900, 1.0.4.62 for R8000, 1.0.2.82 for RAX15 and RAX20, and 1.0.3.106 for RAX200, RAX75, and RAX80.
Where can I find more information about CVE-2021-45674?
More information about CVE-2021-45674 can be found in the Netgear Security Advisory for Stored Cross-Site Scripting on Some Routers (PSV-2020-0017).