CVE-2021-45669
published 2021-12-26CVE-2021-45669: Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72…
PriorityP420medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.42%
33.9th percentile
Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | mr60_firmware | < 1.0.6.110 | 1.0.6.110 |
| netgear | ms60_firmware | < 1.0.6.110 | 1.0.6.110 |
| netgear | rax15_firmware | < 1.0.2.82 | 1.0.2.82 |
| netgear | rax200_firmware | < 1.0.3.106 | 1.0.3.106 |
| netgear | rax20_firmware | < 1.0.2.82 | 1.0.2.82 |
| netgear | rax45_firmware | < 1.0.2.72 | 1.0.2.72 |
| netgear | rax50_firmware | < 1.0.2.72 | 1.0.2.72 |
| netgear | rax75_firmware | < 1.0.3.106 | 1.0.3.106 |
| netgear | rax80_firmware | < 1.0.3.106 | 1.0.3.106 |
| netgear | rbk752_firmware | < 3.2.16.6 | 3.2.16.6 |
| netgear | rbk852_firmware | < 3.2.16.6 | 3.2.16.6 |
| netgear | rbr750_firmware | < 3.2.16.6 | 3.2.16.6 |
| netgear | rbr850_firmware | < 3.2.16.6 | 3.2.16.6 |
| netgear | rbs750_firmware | < 3.2.16.6 | 3.2.16.6 |
| netgear | rbs850_firmware | < 3.2.16.6 | 3.2.16.6 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
WebAuthn4J Spring Security Improper signature counter value handling
ghsa·2023-10-17
CVE-2023-45669 [MEDIUM] CWE-287 WebAuthn4J Spring Security Improper signature counter value handling
WebAuthn4J Spring Security Improper signature counter value handling
Improper signature counter value handling
### Impact
A flaw was found in webauthn4j-spring-security-core. When an authneticator returns an incremented signature counter value during authentication, webauthn4j-spring-security-core does not properly persist the value, which means cloned authenticator detection does not work.
An attacker who cloned valid authenticator in some way can use the cloned authenticator without being detected.
### Patches
Please upgrade to `com.webauthn4j:webauthn4j-spring-security-core:0.9.1.RELEASE`
### References
For more details about WebAuthn signature counters, see [WebAuthn specification 6.1.1. Signature Counter Considerations](https://www.w3.org/TR/2021/REC-webauthn-2-20210408/#sctn-
GHSA
GHSA-5wvp-p978-hpq5: Certain NETGEAR devices are affected by stored XSS
ghsa_unreviewed·2021-12-27
CVE-2021-45669 [MEDIUM] CWE-79 GHSA-5wvp-p978-hpq5: Certain NETGEAR devices are affected by stored XSS
Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-26
Published