VYPR
Unrated severityNVD Advisory· Published Apr 23, 2020· Updated Aug 5, 2024

CVE-2018-21138

CVE-2018-21138

Description

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR D3600 and D6000 routers before firmware 1.0.0.76 have a security misconfiguration allowing adjacent attackers to compromise devices.

Vulnerability

A security misconfiguration exists in NETGEAR D3600 and D6000 modem routers running firmware versions prior to 1.0.0.76. The exact nature of the misconfiguration is not detailed in the advisory, but it affects the device's security settings, potentially exposing services or interfaces that should be restricted [1].

Exploitation

An attacker on the same adjacent network (AV:A) can exploit this vulnerability without authentication (PR:N) and without user interaction (UI:N). The low attack complexity (AC:L) suggests that no special conditions or race windows are required. The attacker can send crafted requests to the vulnerable device to trigger the misconfiguration [1].

Impact

Successful exploitation leads to high confidentiality, integrity, and availability impact (C:H/I:H/A:H). An attacker could gain full control over the device, read sensitive information, modify settings, or disrupt service. The scope is unchanged (S:U), meaning the compromise is limited to the affected device [1].

Mitigation

NETGEAR has released firmware version 1.0.0.76 for both D3600 and D6000 to address this vulnerability. Users should download and install the latest firmware from NETGEAR Support as soon as possible. No workarounds are provided; upgrading is the only mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.