CVE-2021-45673
Summary
| CVE | CVE-2021-45673 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-26 01:15:00 UTC |
| Updated | 2022-01-05 15:06:00 UTC |
| Description | Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P before 1.3.3.140, and RAX75 before 1.0.3.106. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | R6900p | - | All | All | All |
| Operating System | Netgear | R6900p Firmware | All | All | All | All |
| Hardware | Netgear | R7000 | - | All | All | All |
| Hardware | Netgear | R7000p | - | All | All | All |
| Operating System | Netgear | R7000p Firmware | All | All | All | All |
| Operating System | Netgear | R7000 Firmware | All | All | All | All |
| Hardware | Netgear | R7900 | - | All | All | All |
| Operating System | Netgear | R7900 Firmware | All | All | All | All |
| Hardware | Netgear | R8000 | - | All | All | All |
| Operating System | Netgear | R8000 Firmware | All | All | All | All |
| Hardware | Netgear | Rax200 | - | All | All | All |
| Operating System | Netgear | Rax200 Firmware | All | All | All | All |
| Hardware | Netgear | Rax75 | - | All | All | All |
| Operating System | Netgear | Rax75 Firmware | All | All | All | All |
| Hardware | Netgear | Rax80 | - | All | All | All |
| Operating System | Netgear | Rax80 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Stored Cross Site Scripting on Some Routers, PSV-2020-0003 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.