VYPR
Unrated severityNVD Advisory· Published Apr 28, 2020· Updated Aug 5, 2024

CVE-2018-21226

CVE-2018-21226

Description

Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authentication bypass in multiple NETGEAR routers allows remote attackers to gain full device control.

Vulnerability

An authentication bypass vulnerability exists in the web interface of several NETGEAR routers. Affected models include JNR1010v2, JWNR2010v5, WNR1000v4, WNR2020, and WNR2050 running firmware versions prior to 1.1.0.48. The vulnerability allows unauthenticated remote attackers to bypass authentication and access administrative functions [1].

Exploitation

The attacker must be on the same local network as the target device (adjacent network) and can exploit the vulnerability without any credentials or user interaction. No special configuration is required to reach the vulnerable code path. The exact steps are not detailed in the advisory, but the CVSS vector indicates the attack complexity is low [1].

Impact

Successful exploitation allows an attacker to bypass authentication and gain full administrative access to the router. This leads to complete compromise of confidentiality, integrity, and availability (CIA) of the device and potentially the network it controls. The attacker can read sensitive information, modify configurations, or disrupt services [1].

Mitigation

NETGEAR released fixed firmware version 1.1.0.48 for all affected models. Users should download and install the latest firmware from the NETGEAR Support site as soon as possible. No workaround is provided. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.