Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Joel Sanchez

#28259of 53,633
9Total CVSS
Vulnerabilities · 1
PT-2021-4801
9.0
2021-09-15
NetGear · Netgear R6020 · CVE-2021-41383
**Name of the Vulnerable Software and Affected Versions** NETGEAR R6020 version 1.0.0.48 **Description** The issue is related to the lack of input validation, allowing an attacker to execute arbitrary shell commands via shell metacharacters in the `ntp server` field. This can be done by exploiting the `setup.cgi` endpoint on the NETGEAR R6020 device. An admin can execute arbitrary shell commands, potentially leading to remote code execution. **Recommendations** For NETGEAR R6020 version 1.0.0.48, consider disabling the `setup.cgi` endpoint or restricting access to it until a patch is available. Avoid using shell metacharacters in the `ntp server` field to minimize the risk of exploitation.