Stored XSS Vulnerability in NETGEAR Routers and Gateways
CVE-2021-38536

4.3MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
11 August 2021

Summary

Certain NETGEAR routers and gateways are susceptible to stored Cross-Site Scripting (XSS), allowing attackers to insert malicious scripts into web pages viewed by other users. This vulnerability affects multiple NETGEAR devices, including the D6200, D7000, and various RAX models. Successful exploitation may lead to unauthorized actions performed on behalf of users, data theft, or other malicious outcomes. Firmware updates are recommended to mitigate this risk.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.