PT-2021-22184 · NetGear · Ex7700+35
Thorsten Schröder
·
Published
2021-08-11
·
Updated
2021-08-19
·
CVE-2021-38527
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CBR40 versions prior to 2.5.0.14
EX6100v2 versions prior to 1.0.1.98
EX6150v2 versions prior to 1.0.1.98
EX6250 versions prior to 1.0.0.132
EX6400 versions prior to 1.0.2.158
EX6400v2 versions prior to 1.0.0.132
EX6410 versions prior to 1.0.0.132
EX6420 versions prior to 1.0.0.132
EX7300 versions prior to 1.0.2.158
EX7300v2 versions prior to 1.0.0.132
EX7320 versions prior to 1.0.0.132
EX7700 versions prior to 1.0.0.216
EX8000 versions prior to 1.0.1.232
R7800 versions prior to 1.0.2.78
RBK12 versions prior to 2.6.1.44
RBR10 versions prior to 2.6.1.44
RBS10 versions prior to 2.6.1.44
RBK20 versions prior to 2.6.1.38
RBR20 versions prior to 2.6.1.36
RBS20 versions prior to 2.6.1.38
RBK40 versions prior to 2.6.1.38
RBR40 versions prior to 2.6.1.36
RBS40 versions prior to 2.6.1.38
RBK50 versions prior to 2.6.1.40
RBR50 versions prior to 2.6.1.40
RBS50 versions prior to 2.6.1.40
RBK752 versions prior to 3.2.16.6
RBR750 versions prior to 3.2.16.6
RBS750 versions prior to 3.2.16.6
RBK852 versions prior to 3.2.16.6
RBR850 versions prior to 3.2.16.6
RBS850 versions prior to 3.2.16.6
RBS40V versions prior to 2.6.2.4
RBS50Y versions prior to 2.6.1.40
RBW30 versions prior to 2.6.2.2
XR500 versions prior to 2.3.2.114
Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
Recommendations
Update CBR40 to version 2.5.0.14 or later.
Update EX6100v2 to version 1.0.1.98 or later.
Update EX6150v2 to version 1.0.1.98 or later.
Update EX6250 to version 1.0.0.132 or later.
Update EX6400 to version 1.0.2.158 or later.
Update EX6400v2 to version 1.0.0.132 or later.
Update EX6410 to version 1.0.0.132 or later.
Update EX6420 to version 1.0.0.132 or later.
Update EX7300 to version 1.0.2.158 or later.
Update EX7300v2 to version 1.0.0.132 or later.
Update EX7320 to version 1.0.0.132 or later.
Update EX7700 to version 1.0.0.216 or later.
Update EX8000 to version 1.0.1.232 or later.
Update R7800 to version 1.0.2.78 or later.
Update RBK12 to version 2.6.1.44 or later.
Update RBR10 to version 2.6.1.44 or later.
Update RBS10 to version 2.6.1.44 or later.
Update RBK20 to version 2.6.1.38 or later.
Update RBR20 to version 2.6.1.36 or later.
Update RBS20 to version 2.6.1.38 or later.
Update RBK40 to version 2.6.1.38 or later.
Update RBR40 to version 2.6.1.36 or later.
Update RBS40 to version 2.6.1.38 or later.
Update RBK50 to version 2.6.1.40 or later.
Update RBR50 to version 2.6.1.40 or later.
Update RBS50 to version 2.6.1.40 or later.
Update RBK752 to version 3.2.16.6 or later.
Update RBR750 to version 3.2.16.6 or later.
Update RBS750 to version 3.2.16.6 or later.
Update RBK852 to version 3.2.16.6 or later.
Update RBR850 to version 3.2.16.6 or later.
Update RBS850 to version 3.2.16.6 or later.
Update RBS40V to version 2.6.2.4 or later.
Update RBS50Y to version 2.6.1.40 or later.
Update RBW30 to version 2.6.2.2 or later.
Update XR500 to version 2.3.2.114 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cbr40
Ex6100V2
Ex6150V2
Ex6250
Ex6400
Ex6400V2
Ex6410
Ex6420
Ex7300
Ex7300V2
Ex7320
Ex7700
Ex8000
R7800
Rbk12
Rbk20
Rbk40
Rbk50
Rbk752
Rbk852
Rbr10
Rbr20
Rbr40
Rbr50
Rbr750
Rbr850
Rbs10
Rbs20
Rbs40
Rbs40V
Rbs50
Rbs50Y
Rbs750
Rbs850
Rbw30
Xr500