CVE-2021-45669Cross-site Scripting in Netgear Mr60 Firmware

Severity
4.8MEDIUMNVD
CNA3.7
EPSS
0.3%
top 49.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26
Latest updateOct 17

Description

Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages15 packages

NVDnetgear/rax200_firmware< 1.0.3.106
NVDnetgear/mr60_firmware< 1.0.6.110
NVDnetgear/ms60_firmware< 1.0.6.110
NVDnetgear/rax15_firmware< 1.0.2.82
NVDnetgear/rax20_firmware< 1.0.2.82

Patches

🔴Vulnerability Details

3
GHSA
WebAuthn4J Spring Security Improper signature counter value handling2023-10-17
GHSA
GHSA-5wvp-p978-hpq5: Certain NETGEAR devices are affected by stored XSS2021-12-27
CVEList
CVE-2021-45669: Certain NETGEAR devices are affected by stored XSS2021-12-26
CVE-2021-45669 — Cross-site Scripting in Netgear | cvebase