CVE-2018-21131

EUVD-2018-13649
Certain NETGEAR devices are affected by unauthenticated firmware downgrade. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
mitreCNA
8.1 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.0/AC:L/AV:A/A:H/C:N/I:H/PR:N/S:U/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
netgearwac505_firmware
𝑥
< 5.0.0.17
netgearwac510_firmware
𝑥
< 5.0.0.17
𝑥
= Vulnerable software versions