VYPR
Unrated severityNVD Advisory· Published Dec 26, 2021· Updated Aug 4, 2024

CVE-2021-45670

CVE-2021-45670

Description

Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before 1.0.11.116, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.3.106, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, EX3700 before 1.0.0.90, MR60 before 1.0.6.110, R7000P before 1.3.2.126, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, EX3800 before 1.0.0.90, MS60 before 1.0.6.110, R6900P before 1.3.2.126, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored cross-site scripting (XSS) vulnerability in multiple NETGEAR routers, extenders, and WiFi systems allows attackers to inject malicious scripts via the web interface.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the web-based management interface of numerous NETGEAR devices. The flaw affects the following models running firmware versions prior to the specified fixed releases: CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before 1.0.11.116, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.3.106, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, EX3700 before 1.0.0.90, MR60 before 1.0.6.110, R7000P before 1.3.2.126, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, EX3800 before 1.0.0.90, MS60 before 1.0.6.110, R6900P before 1.3.2.126, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6 [1]. The vulnerability is classified as stored XSS, meaning the injected script is permanently stored on the device and executed when the page is loaded by an administrator.

Exploitation

An attacker must be authenticated to the device's web interface to exploit this vulnerability. The attacker can inject malicious script code into input fields that are later displayed to other users, such as the device's configuration pages. The exact input vectors are not detailed in the advisory, but typical stored XSS in router interfaces involves fields like SSID names, device names, or other configuration parameters. Once the malicious script is stored, any administrator accessing the affected page will execute the script in their browser context.

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the administrator's browser session. This can lead to session hijacking, theft of sensitive information (e.g., admin credentials), or further compromise of the device's configuration. The impact is limited to the web interface and does not directly allow remote code execution on the device itself, but it can be used to escalate privileges or perform actions on behalf of the administrator.

Mitigation

NETGEAR has released firmware updates for all affected models. Users should upgrade to the fixed versions listed above as soon as possible [1]. The advisory does not mention any workarounds. No evidence of exploitation in the wild has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.