CVE-2018-21164
Description
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated command injection in NETGEAR R6220 and WNDR3700v5 routers allows full compromise; fixed in firmware 1.1.0.64 and 1.1.0.54.
Vulnerability
A post-authentication command injection vulnerability exists in certain NETGEAR routers, specifically the R6220 and WNDR3700v5 models. Affected versions are R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54. The vulnerability allows an authenticated user to inject arbitrary commands via the router's web interface, as described in the NETGEAR security advisory [1].
Exploitation
Exploitation requires an attacker to have valid authentication credentials for the router's administrative interface. The attacker must be on the same network or have remote access to the management interface. The exact steps are not detailed publicly, but the advisory confirms that command injection can be performed by sending specially crafted requests to vulnerable firmware [1].
Impact
Successful exploitation grants the attacker the ability to execute arbitrary commands with root privileges on the device, leading to full compromise of confidentiality, integrity, and availability (CIA) of the router and potentially the network it supports [1].
Mitigation
NETGEAR has released fixed firmware versions: 1.1.0.64 for R6220 and 1.1.0.54 for WNDR3700v5. Users are strongly advised to download and install the latest firmware from the NETGEAR Support site to remediate the vulnerability. No workaround is available [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- NETGEAR/NETGEAR devicesdescription
- Range: <1.1.0.54
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.