CVE & CISA-KEV Catalog

CVE-2021-40867

HIGH
7.8
CVSS v3
NVD

Description

Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who uses the same source IP address as an admin in the process of logging in (e.g., behind the same NAT device, or already in possession of a foothold on an admin's machine). This occurs because the multi-step HTTP authentication process is effectively tied only to the source IP address. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

How to fix

Remediation Available
gc108p firmwareNVD
Affected:< 1.0.8.2Fixed in:1.0.8.2CVE-2021-40867derived from NVD
gc108pp firmwareNVD
Affected:< 1.0.8.2Fixed in:1.0.8.2CVE-2021-40867derived from NVD
gs108t firmwareNVD
Affected:< 7.0.7.2Fixed in:7.0.7.2CVE-2021-40867derived from NVD
gs110tp firmwareNVD
Affected:< 7.0.7.2Fixed in:7.0.7.2CVE-2021-40867derived from NVD
gs110tpp firmwareNVD
Affected:< 7.0.7.2Fixed in:7.0.7.2CVE-2021-40867derived from NVD
gs110tup firmwareNVD
Affected:< 1.0.5.3Fixed in:1.0.5.3CVE-2021-40867derived from NVD
gs308t firmwareNVD
Affected:< 1.0.3.2Fixed in:1.0.3.2CVE-2021-40867derived from NVD
gs310tp firmwareNVD
Affected:< 1.0.3.2Fixed in:1.0.3.2CVE-2021-40867derived from NVD
gs710tup firmwareNVD
Affected:< 1.0.5.3Fixed in:1.0.5.3CVE-2021-40867derived from NVD
gs716tp firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD
gs716tpp firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD
gs724tp firmwareNVD
Affected:< 2.0.6.3Fixed in:2.0.6.3CVE-2021-40867derived from NVD
gs724tpp firmwareNVD
Affected:< 2.0.6.3Fixed in:2.0.6.3CVE-2021-40867derived from NVD
gs728tp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
gs728tpp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
gs750e firmwareNVD
Affected:< 1.0.1.10Fixed in:1.0.1.10CVE-2021-40867derived from NVD
gs752tp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
gs752tpp firmwareNVD
Affected:< 6.0.8.2Fixed in:6.0.8.2CVE-2021-40867derived from NVD
ms510txm firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD
ms510txup firmwareNVD
Affected:< 1.0.4.2Fixed in:1.0.4.2CVE-2021-40867derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploit Intelligence

1.36%probability of exploitation in 30 days
68thpercentile

Moderate risk: more likely to be exploited than 68% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2021-40867
CVE-2021-40867 severity badge

Markdown

[![CVE-2021-40867](https://tridentstack.com/cve/badge/CVE-2021-40867.svg)](https://tridentstack.com/cve/CVE-2021-40867)

HTML

<a href="https://tridentstack.com/cve/CVE-2021-40867"><img src="https://tridentstack.com/cve/badge/CVE-2021-40867.svg" alt="CVE-2021-40867"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.