CVE-2018-21139

Severity
7.5HIGH
EPSS
0.3%
top 50.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateMay 24

Description

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.58, D6200 before 1.1.00.30, D6220 before 1.0.0.46, D6400 before 1.0.0.82, D7000 before 1.0.1.68, D7000v2 before 1.0.0.51, D7800 before 1.0.1.42, D8500 before 1.0.3.42, DC112A before 1.0.0.40, DGN2200Bv4 before 1.0.0.102, DGN2200v4 before 1.0.0.102, JNR1010v2 before 1.1.0.54, JR6150 before 1.0.1.18, JWNR2010v5 before 1.1.0.54, PR2000 before 1.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages49 packages

NVDnetgear/r6900p_firmware< 1.3.1.44
NVDnetgear/r7000p_firmware< 1.3.1.44
NVDnetgear/r7900p_firmware< 1.4.1.24
NVDnetgear/r8000p_firmware< 1.4.1.24
NVDnetgear/d500_firmware< 1.0.0.27

🔴Vulnerability Details

2
GHSA
GHSA-87jj-5mq8-98pw: Certain NETGEAR devices are affected by disclosure of sensitive information2022-05-24
CVEList
CVE-2018-21139: Certain NETGEAR devices are affected by disclosure of sensitive information2020-04-23
CVE-2018-21139 (HIGH CVSS 7.5) | Certain NETGEAR devices are affecte | cvebase.io