VYPR
Unrated severityNVD Advisory· Published Apr 22, 2020· Updated Aug 5, 2024

CVE-2018-21128

CVE-2018-21128

Description

Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR WAC505 and WAC510 access points before 5.0.0.17 are vulnerable to authentication bypass, allowing a nearby attacker to gain complete control with no credentials.

Vulnerability

An authentication bypass vulnerability exists in NETGEAR WAC505 and WAC510 wireless access points running firmware versions prior to 5.0.0.17 [1]. The flaw is present in the device's authentication mechanism, allowing an attacker to bypass login procedures without valid credentials [1]. No authentication is required to trigger the vulnerability, and the code path is reachable by default on affected firmware versions [1].

Exploitation

An attacker must be on the same local network as the affected access point (adjacent network position) to exploit this vulnerability [1]. No authentication or user interaction is required [1]. The attacker can send specially crafted network requests to the vulnerable device to bypass authentication and gain administrative access [1].

Impact

Successful exploitation allows an attacker to gain complete control over the affected access point with high privileges [1]. The impact includes full compromise of confidentiality, integrity, and availability (CIA triad) since CVSS v3 indicates High impact on all three dimensions [1]. An attacker can change settings, intercept traffic, or use the device as a pivot point within the network [1].

Mitigation

NETGEAR has released firmware version 5.0.0.17 for both WAC505 and WAC510 to fix this vulnerability [1]. Users are strongly recommended to download and install the latest firmware from NETGEAR Support as soon as possible [1]. There are no known workarounds mentioned in the advisory; applying the firmware update is the only mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.