PT-2021-22175 · NetGear · Netgear Rbr850+4
Published
2021-08-11
·
Updated
2021-08-18
·
CVE-2021-38518
CVSS v3.1
8.4
High
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:H/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
NETGEAR RAX200 versions prior to 1.0.4.120
NETGEAR RAX75 versions prior to 1.0.4.120
NETGEAR RAX80 versions prior to 1.0.4.120
NETGEAR RBK852 versions prior to 3.2.17.12
NETGEAR RBR850 versions prior to 3.2.17.12
NETGEAR RBS850 versions prior to 3.2.17.12
Description
Certain NETGEAR devices are affected by command injection by an authenticated user.
Recommendations
For NETGEAR RAX200 versions prior to 1.0.4.120, update to version 1.0.4.120 or later.
For NETGEAR RAX75 versions prior to 1.0.4.120, update to version 1.0.4.120 or later.
For NETGEAR RAX80 versions prior to 1.0.4.120, update to version 1.0.4.120 or later.
For NETGEAR RBK852 versions prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBR850 versions prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBS850 versions prior to 3.2.17.12, update to version 3.2.17.12 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Rax200
Netgear Rax75
Netgear Rax80
Netgear Rbk852
Netgear Rbr850