CVE-2021-38513

Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, RBK752 before 3.2.10.10, RBR750 before 3.2.10.10, and RBS750 before 3.2.10.10.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rbk852_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk852:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:cbr40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:cbr40:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:eax20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:eax20:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:mk62_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mk62:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rbk752_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk752:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:17

Type Values Removed Values Added
References () https://kb.netgear.com/000063777/Security-Advisory-for-Authentication-Bypass-on-Some-Extenders-and-WiFi-Systems-PSV-2020-0008 - Vendor Advisory () https://kb.netgear.com/000063777/Security-Advisory-for-Authentication-Bypass-on-Some-Extenders-and-WiFi-Systems-PSV-2020-0008 - Vendor Advisory
CVSS v2 : 10.0
v3 : 9.8
v2 : 10.0
v3 : 9.6

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-287 NVD-CWE-noinfo

18 Aug 2021, 15:08

Type Values Removed Values Added
CWE CWE-287
CPE cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:eax20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:cbr40:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:mk62_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk752:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:cbr40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbk752_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:eax20:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk852:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbk852_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mk62:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
References (MISC) https://kb.netgear.com/000063777/Security-Advisory-for-Authentication-Bypass-on-Some-Extenders-and-WiFi-Systems-PSV-2020-0008 - (MISC) https://kb.netgear.com/000063777/Security-Advisory-for-Authentication-Bypass-on-Some-Extenders-and-WiFi-Systems-PSV-2020-0008 - Vendor Advisory

11 Aug 2021, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-11 00:15

Updated : 2024-11-21 06:17


NVD link : CVE-2021-38513

Mitre link : CVE-2021-38513

CVE.ORG link : CVE-2021-38513


JSON object : View

Products Affected

netgear

  • rbr850
  • ms60
  • eax20_firmware
  • eax20
  • cbr40
  • rbk752_firmware
  • rbr850_firmware
  • rbk752
  • rbk852
  • ms60_firmware
  • rbs750
  • rbs750_firmware
  • mr60_firmware
  • mr60
  • rbr750
  • mk62_firmware
  • rbr750_firmware
  • rbs850
  • cbr40_firmware
  • mk62
  • rbk852_firmware
  • rbs850_firmware