cbcvebase.
CVE-2021-45511
published 2021-12-26

CVE-2021-45511: Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOIT
Exploited in the wild
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000 before 2021-08-27, R6220 before 2021-08-27, R6230 before 2021-08-27, R6260 before 2021-08-27, R6330 before 2021-08-27, R6350 before 2021-08-27, R6700v2 before 2021-08-27, R6800 before 2021-08-27, R6850 before 2021-08-27, R6900v2 before 2021-08-27, R7200 before 2021-08-27, R7350 before 2021-08-27, R7400 before 2021-08-27, and R7450 before 2021-08-27.

Affected

17 ranges
VendorProductVersion rangeFixed in
netgearac2100_firmware< 1.2.0.881.2.0.88
netgearac2400_firmware< 1.2.0.881.2.0.88
netgearac2600_firmware< 1.2.0.881.2.0.88
netgeard7000_firmware< 1.0.1.801.0.1.80
netgearr6220_firmware< 1.1.0.1101.1.0.110
netgearr6230_firmware< 1.1.0.1101.1.0.110
netgearr6260_firmware< 1.1.0.841.1.0.84
netgearr6330_firmware< 1.1.0.841.1.0.84
netgearr6350_firmware< 1.1.0.841.1.0.84
netgearr6700v2_firmware< 1.2.0.881.2.0.88
netgearr6800_firmware< 1.2.0.881.2.0.88
netgearr6850_firmware< 1.1.0.841.1.0.84
netgearr6900v2_firmware< 1.2.0.881.2.0.88
netgearr7200_firmware< 1.2.0.881.2.0.88
netgearr7350_firmware< 1.2.0.881.2.0.88
netgearr7400_firmware< 1.2.0.881.2.0.88
netgearr7450_firmware< 1.2.0.881.2.0.88

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck6.8MEDIUM