Security readout for executives and security teams
Plain-English summary
A broad set of NETGEAR routers, extenders, and smart cradles can disclose sensitive information when running older firmware. The issue is high severity because it requires no authentication or user interaction, but the CVSS vector indicates an adjacent-network attacker rather than a remote internet attacker.
Executive priority
Prioritize remediation where affected NETGEAR devices protect business networks or serve shared Wi-Fi. This is not confirmed as actively exploited in the supplied sources, but the unauthenticated sensitive-data exposure and broad model list justify timely patching or replacement.
Technical view
CVE-2018-21139 is a sensitive information disclosure vulnerability affecting many NETGEAR D-series, R-series, WN-series, and related devices before model-specific firmware versions. CVSS 3.0 is 7.1 with AV:A, AC:L, PR:N, UI:N, C:H, I:L, A:N. No CWE or detailed vulnerable interface is provided in the source bundle.
Likely exposure
Exposure is most likely where listed NETGEAR models remain in service below the fixed firmware versions, especially on shared LAN, Wi-Fi, guest, branch, or unmanaged small-office networks.
Exploitation context
The supplied sources do not show CISA KEV listing or other evidence of active exploitation. The adjacent-network vector suggests exploitation would require network proximity, such as access to the same local or wireless network.
Researcher notes
The source bundle gives affected models and fixed-version thresholds but not root cause, endpoint, proof of concept, or exposed data type. Avoid assuming internet reachability; CVSS marks adjacent attack vector. Affected CPE and CWE data are absent in the provided CVE metadata.
Mitigation direction
- Identify listed NETGEAR models in use and record their firmware versions.
- Update each affected device to the vendor-fixed firmware version or later.
- Check the NETGEAR advisory for model-specific firmware guidance.
- Replace unsupported devices if fixed firmware is unavailable or cannot be installed.
- Restrict access to router management networks and untrusted Wi-Fi segments.
Validation and detection
- Compare each device model and firmware against the CVE affected-version list.
- Confirm upgraded devices report firmware at or above the listed fixed version.
- Review network segmentation for guest, Wi-Fi, and management access paths.
- Check vendor guidance for any additional model-specific validation steps.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-21139 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.1 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AC:L/AV:A/A:N/C:H/I:L/PR:N/S:U/UI:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AC:L/AV:A/A:N/C:H/I:L/PR:N/S:U/UI:N2.84.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
7.1HighVector: CVSS:3.0/AC:L/AV:A/A:N/C:H/I:L/PR:N/S:U/UI:N
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.netgear.com/000060220/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-and-Smart-Cradles-PSV-2017-2198CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
