VYPR
Unrated severityNVD Advisory· Published Apr 27, 2020· Updated Aug 5, 2024

CVE-2018-21154

CVE-2018-21154

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, and R7800 before 1.0.2.42.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated command injection in multiple NETGEAR devices allows attackers to execute arbitrary commands with root privileges.

Vulnerability

A post-authentication command injection vulnerability exists in the web management interface of several NETGEAR gateways and routers. Affected models include D7800 (before firmware 1.0.1.34), DM200 (before 1.0.0.50), R6100 (before 1.0.1.22), R7500 (before 1.0.0.122), R7500v2 (before 1.0.3.26), and R7800 (before 1.0.2.42). The vulnerability is reachable only after a user has authenticated to the device's administrative interface [1].

Exploitation

An attacker must possess valid credentials for the device's web-based management interface. Once authenticated, the attacker can send specially crafted HTTP requests to inject arbitrary operating system commands through a vulnerable input parameter. No additional user interaction or network position beyond local network access is required [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with root-level privileges on the affected device. This can lead to full compromise of the device, including disclosure of sensitive information, modification of device configuration, and potential use as a pivot point for further attacks on the local network [1].

Mitigation

NETGEAR has released fixed firmware versions for all affected models. Users should upgrade to the following versions or later: D7800 to 1.0.1.34, DM200 to 1.0.0.50, R6100 to 1.0.1.22, R7500 to 1.0.0.122, R7500v2 to 1.0.3.26, and R7800 to 1.0.2.42. No workarounds are available; updating the firmware is the only recommended mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.