PT-2021-5918 · NetGear · Rbr750+21
Published
2021-09-26
·
Updated
2022-01-10
·
CVE-2021-45614
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR D7000v2 versions prior to 1.0.0.74
NETGEAR LAX20 versions prior to 1.1.6.28
NETGEAR MK62 versions prior to 1.0.6.116
NETGEAR MR60 versions prior to 1.0.6.116
NETGEAR MS60 versions prior to 1.0.6.116
NETGEAR RAX15 versions prior to 1.0.3.96
NETGEAR RAX20 versions prior to 1.0.3.96
NETGEAR RAX200 versions prior to 1.0.4.120
NETGEAR RAX45 versions prior to 1.0.3.96
NETGEAR RAX50 versions prior to 1.0.3.96
NETGEAR RAX43 versions prior to 1.0.3.96
NETGEAR RAX40v2 versions prior to 1.0.3.96
NETGEAR RAX35v2 versions prior to 1.0.3.96
NETGEAR RAX75 versions prior to 1.0.4.120
NETGEAR RAX80 versions prior to 1.0.4.120
NETGEAR RBK752 versions prior to 3.2.17.12
NETGEAR RBR750 versions prior to 3.2.17.12
NETGEAR RBS750 versions prior to 3.2.17.12
NETGEAR RBK852 versions prior to 3.2.17.12
NETGEAR RBR850 versions prior to 3.2.17.12
NETGEAR RBS850 versions prior to 3.2.17.12
NETGEAR XR1000 versions prior to 1.0.0.58
Description
The issue is related to insufficient input data cleaning, which can allow a remote attacker to execute arbitrary commands. This is a command injection issue that affects certain NETGEAR devices.
Recommendations
For NETGEAR D7000v2 version prior to 1.0.0.74, update to version 1.0.0.74 or later.
For NETGEAR LAX20 version prior to 1.1.6.28, update to version 1.1.6.28 or later.
For NETGEAR MK62 version prior to 1.0.6.116, update to version 1.0.6.116 or later.
For NETGEAR MR60 version prior to 1.0.6.116, update to version 1.0.6.116 or later.
For NETGEAR MS60 version prior to 1.0.6.116, update to version 1.0.6.116 or later.
For NETGEAR RAX15 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX20 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX200 version prior to 1.0.4.120, update to version 1.0.4.120 or later.
For NETGEAR RAX45 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX50 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX43 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX40v2 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX35v2 version prior to 1.0.3.96, update to version 1.0.3.96 or later.
For NETGEAR RAX75 version prior to 1.0.4.120, update to version 1.0.4.120 or later.
For NETGEAR RAX80 version prior to 1.0.4.120, update to version 1.0.4.120 or later.
For NETGEAR RBK752 version prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBR750 version prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBS750 version prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBK852 version prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBR850 version prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR RBS850 version prior to 3.2.17.12, update to version 3.2.17.12 or later.
For NETGEAR XR1000 version prior to 1.0.0.58, update to version 1.0.0.58 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D7000V2
Lax20
Mk62
Mr60
Ms60
Rax15
Rax20
Rax200
Rax35V2
Rax40V2
Rax43
Rax45
Rax50
Rax75
Rax80
Rbk752
Rbk852
Rbr750
Rbr850
Rbs750
Rbs850
Xr1000