PT-2021-5917 · NetGear · Netgear Xr500+2

Fr33Rh

·

Published

2021-12-20

·

Updated

2022-01-05

·

CVE-2021-45623

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R7800 versions prior to 1.0.2.74 NETGEAR R9000 versions prior to 1.0.5.2 NETGEAR XR500 versions prior to 2.3.2.66
Description The issue is related to insufficient input validation, allowing an unauthenticated attacker to perform command injection. This can enable a remote attacker to execute arbitrary commands.
Recommendations For NETGEAR R7800 versions prior to 1.0.2.74, update to version 1.0.2.74 or later. For NETGEAR R9000 versions prior to 1.0.5.2, update to version 1.0.5.2 or later. For NETGEAR XR500 versions prior to 2.3.2.66, update to version 2.3.2.66 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00432
CVE-2021-45623

Affected Products

Netgear R7800
Netgear R9000
Netgear Xr500