CVE-2021-38514

Severity
2.7LOW
EPSS
0.2%
top 60.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.52, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before 1.0.0.108, DGND2200Bv4 before 1.0.0.108, EX2700 before 1.0.1.48, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6000 before 1.0.0.38, EX6100 before

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages74 packages

NVDnetgear/pr2000_firmware< 1.0.0.28
NVDnetgear/r6900p_firmware< 1.3.1.64
NVDnetgear/r7000p_firmware< 1.3.1.64
NVDnetgear/r7900p_firmware< 1.4.1.30
NVDnetgear/r8000p_firmware< 1.4.1.30

🔴Vulnerability Details

2
GHSA
GHSA-3mfx-6prr-4g43: Certain NETGEAR devices are affected by authentication bypass2022-05-24
CVEList
CVE-2021-38514: Certain NETGEAR devices are affected by authentication bypass2021-08-10
CVE-2021-38514 (LOW CVSS 2.7) | Certain NETGEAR devices are affecte | cvebase.io