VYPR
Unrated severityNVD Advisory· Published Apr 27, 2020· Updated Aug 5, 2024

CVE-2018-21095

CVE-2018-21095

Description

NETGEAR SRR60 and SRS60 devices before firmware 2.2.1.210 are vulnerable to stored cross-site scripting (XSS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR SRR60 and SRS60 devices before firmware 2.2.1.210 are vulnerable to stored cross-site scripting (XSS).

Vulnerability

NETGEAR SRR60 and SRS60 devices running firmware versions prior to 2.2.1.210 are affected by a stored cross-site scripting (XSS) vulnerability [1]. The vulnerability resides in the web interface and can be triggered when an authenticated user with high privileges inputs malicious script that is stored and later executed in the context of other users' sessions.

Exploitation

An attacker must have high privileges (e.g., administrator) on the device to inject the malicious script via the web interface. The stored script is then executed when other users (including those with lower privileges) access the affected page, requiring user interaction (viewing the page) [1]. The attack vector is adjacent network (CVSS:3.0/AV:A) meaning the attacker must be on the same local network as the device.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to disclosure of sensitive information (e.g., session tokens) or limited modification of web content (CVSS Confidentiality and Integrity Low) [1]. The scope is changed (S:C) meaning the impact extends beyond the vulnerable component.

Mitigation

NETGEAR has released firmware version 2.2.1.210 for both SRR60 and SRS60 to fix this vulnerability [1]. Users should update to the latest firmware as soon as possible. No workarounds are mentioned. The device is not listed on CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.