QSearchQSearch

CVE-2021-38537

4.2 MEDIUM

Certain NETGEAR devices are affected by stored XSS

Published: 2021-08-11 · Last updated: 2026-06-17

Severity and scoring

CVSS
4.2 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE
CWE-79

Affected products

VendorProduct
netgearac2100_firmware, ac2400_firmware, ac2600_firmware

Description

Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R6850 before 1.1.0.78, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, AC2600 before 1.2.0.76, and RAX40 before 1.0.3.62.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-40847 The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execu... (8.1 HIGH)
  • CVE-2021-41383 setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_serve... (7.2 HIGH)
  • CVE-2021-41314 Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of th... (8.8 HIGH)
  • CVE-2021-40867 Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker wh... (7.8 HIGH)
  • CVE-2021-40866 Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (disabled by default... (9.8 CRITICAL)

Same CWE

  • CVE-2026-12425 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
  • CVE-2024-30476 PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
  • CVE-2026-54198 Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
  • CVE-2026-54191 Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
  • CVE-2026-39437 Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)