CVE-2018-21095
Description
NETGEAR SRR60 and SRS60 devices before firmware 2.2.1.210 are vulnerable to stored cross-site scripting (XSS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NETGEAR SRR60 and SRS60 devices before firmware 2.2.1.210 are vulnerable to stored cross-site scripting (XSS).
Vulnerability
NETGEAR SRR60 and SRS60 devices running firmware versions prior to 2.2.1.210 are affected by a stored cross-site scripting (XSS) vulnerability [1]. The vulnerability resides in the web interface and can be triggered when an authenticated user with high privileges inputs malicious script that is stored and later executed in the context of other users' sessions.
Exploitation
An attacker must have high privileges (e.g., administrator) on the device to inject the malicious script via the web interface. The stored script is then executed when other users (including those with lower privileges) access the affected page, requiring user interaction (viewing the page) [1]. The attack vector is adjacent network (CVSS:3.0/AV:A) meaning the attacker must be on the same local network as the device.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to disclosure of sensitive information (e.g., session tokens) or limited modification of web content (CVSS Confidentiality and Integrity Low) [1]. The scope is changed (S:C) meaning the impact extends beyond the vulnerable component.
Mitigation
NETGEAR has released firmware version 2.2.1.210 for both SRR60 and SRS60 to fix this vulnerability [1]. Users should update to the latest firmware as soon as possible. No workarounds are mentioned. The device is not listed on CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- NETGEAR/SRR60description
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.