CVE & CISA-KEV Catalog

CVE-2021-40867

HIGH
7.8
CVSS v3
NVD

Description

Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who uses the same source IP address as an admin in the process of logging in (e.g., behind the same NAT device, or already in possession of a foothold on an admin's machine). This occurs because the multi-step HTTP authentication process is effectively tied only to the source IP address. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

How to fix

Remediation Available
gc108p firmwareNVD
Affected:< 1.0.8.2Fixed in:1.0.8.2CVE-2021-40867derived from NVD
gc108pp firmwareNVD
Affected:< 1.0.8.2Fixed in:1.0.8.2CVE-2021-40867derived from NVD
gs108t firmwareNVD
Affected:< 7.0.7.2Fixed in:7.0.7.2CVE-2021-40867derived from NVD
gs110tp firmwareNVD
Affected:< 7.0.7.2Fixed in:7.0.7.2CVE-2021-40867derived from NVD
gs110tpp firmwareNVD
Affected:< 7.0.7.2Fixed in:7.0.7.2CVE-2021-40867derived from NVD
gs110tup firmwareNVD
Affected:< 1.0.5.3Fixed in:1.0.5.3CVE-2021-40867derived from NVD
gs308t firmwareNVD
Affected:< 1.0.3.2Fixed in:1.0.3.2CVE-2021-40867derived from NVD
gs310tp firmwareNVD
Affected:< 1.0.3.2Fixed in:1.0.3.2CVE-2021-40867derived from NVD
gs710tup firmwareNVD
Affected:< 1.0.5.3Fixed in:1.0.5.3CVE-2021-40867derived from NVD
gs716tp firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD
gs716tpp firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD
gs724tp firmwareNVD
Affected:< 2.0.6.3Fixed in:2.0.6.3CVE-2021-40867derived from NVD
gs724tpp firmwareNVD
Affected:< 2.0.6.3Fixed in:2.0.6.3CVE-2021-40867derived from NVD
gs728tp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
gs728tpp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
gs750e firmwareNVD
Affected:< 1.0.1.10Fixed in:1.0.1.10CVE-2021-40867derived from NVD
gs752tp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
gs752tpp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
ms510txm firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD
ms510txup firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploit Intelligence

1.40%probability of exploitation in 30 days
70thpercentile

Moderate risk: more likely to be exploited than 70% of all known CVEs.

References

Vendor Advisory1

Related Vulnerabilities

Other CWE-290 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2024-4358Critical9.897%KEV-
CVE-2022-24112Critical9.896%KEVFix
CVE-2022-23131Critical9.196%KEV-
CVE-2019-1234High7.574%--
CVE-2021-31195Medium6.574%-Fix
CVE-2020-7388Critical10.069%-Fix

Common questions

How do I fix CVE-2021-40867?

Published advisories record a fix for 20 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2021-40867 being actively exploited?

Not that we know of. CVE-2021-40867 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 1.4% is the estimated probability that it will be exploited in the next 30 days. That is higher than 70% of all scored CVEs.

How severe is CVE-2021-40867?

CVE-2021-40867 has a CVSS v3 base score of 7.8, rated high. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2021-40867 affect?

Published advisories record a fix for gc108p firmware (NVD), gc108pp firmware (NVD), gs108t firmware (NVD), gs110tp firmware (NVD), and 16 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2021-40867
CVE-2021-40867 severity badge

Markdown

[![CVE-2021-40867](https://tridentstack.com/cve/badge/CVE-2021-40867.svg)](https://tridentstack.com/cve/CVE-2021-40867)

HTML

<a href="https://tridentstack.com/cve/CVE-2021-40867"><img src="https://tridentstack.com/cve/badge/CVE-2021-40867.svg" alt="CVE-2021-40867"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.