CVE-2021-38516 is a critical vulnerability affecting numerous NETGEAR devices, stemming from a lack of proper access control at the function level. This flaw impacts a wide range of routers and mesh Wi-Fi systems, including models from the D, R, RBK, and WNR series, among others, across various firmware versions. Rated with a CVSS score of 9.8 (CRITICAL), the vulnerability can be exploited remotely over the network with low attack complexity, requiring no user interaction or prior privileges. Successful exploitation could lead to complete compromise of confidentiality, integrity, and availability of the affected device. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a significant percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.48CPE matchmatch criteria | cpe:2.3:o:netgear:d6220_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.82CPE matchmatch criteria | cpe:2.3:o:netgear:d6400_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.52CPE matchmatch criteria | cpe:2.3:o:netgear:d7000_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.44CPE matchmatch criteria | cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.3.43CPE matchmatch criteria | cpe:2.3:o:netgear:d8500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.