PT-2021-5957 · NetGear · Netgear R7800+16

Kevin Breen

·

Published

2021-05-03

·

Updated

2022-07-12

·

CVE-2021-45602

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR D7800 versions 1.0.1.66 and earlier NETGEAR EX2700 versions 1.0.1.68 and earlier NETGEAR WN3000RPv2 versions 1.0.0.90 and earlier NETGEAR WN3000RPv3 versions 1.0.2.100 and earlier NETGEAR LBR1020 versions 2.6.5.20 and earlier NETGEAR LBR20 versions 2.6.5.32 and earlier NETGEAR R6700AX versions 1.0.10.110 and earlier NETGEAR R7800 versions 1.0.2.86 and earlier NETGEAR R8900 versions 1.0.5.38 and earlier NETGEAR R9000 versions 1.0.5.38 and earlier NETGEAR RAX10 versions 1.0.10.110 and earlier NETGEAR RAX120v1 versions 1.2.3.28 and earlier NETGEAR RAX120v2 versions 1.2.3.28 and earlier NETGEAR RAX70 versions 1.0.10.110 and earlier NETGEAR RAX78 versions 1.0.10.110 and earlier NETGEAR XR450 versions 2.3.2.130 and earlier NETGEAR XR500 versions 2.3.2.130 and earlier NETGEAR XR700 versions 1.0.1.46 and earlier
Description The issue is related to command injection by an authenticated user due to the lack of input data sanitization. This can allow an attacker to execute arbitrary commands or gain unauthorized access to protected information by sending a specially crafted request to the UPNP port.
Recommendations For NETGEAR D7800 versions 1.0.1.66 and earlier, update to version 1.0.1.66 or later. For NETGEAR EX2700 versions 1.0.1.68 and earlier, update to version 1.0.1.68 or later. For NETGEAR WN3000RPv2 versions 1.0.0.90 and earlier, update to version 1.0.0.90 or later. For NETGEAR WN3000RPv3 versions 1.0.2.100 and earlier, update to version 1.0.2.100 or later. For NETGEAR LBR1020 versions 2.6.5.20 and earlier, update to version 2.6.5.20 or later. For NETGEAR LBR20 versions 2.6.5.32 and earlier, update to version 2.6.5.32 or later. For NETGEAR R6700AX versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later. For NETGEAR R7800 versions 1.0.2.86 and earlier, update to version 1.0.2.86 or later. For NETGEAR R8900 versions 1.0.5.38 and earlier, update to version 1.0.5.38 or later. For NETGEAR R9000 versions 1.0.5.38 and earlier, update to version 1.0.5.38 or later. For NETGEAR RAX10 versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later. For NETGEAR RAX120v1 versions 1.2.3.28 and earlier, update to version 1.2.3.28 or later. For NETGEAR RAX120v2 versions 1.2.3.28 and earlier, update to version 1.2.3.28 or later. For NETGEAR RAX70 versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later. For NETGEAR RAX78 versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later. For NETGEAR XR450 versions 2.3.2.130 and earlier, update to version 2.3.2.130 or later. For NETGEAR XR500 versions 2.3.2.130 and earlier, update to version 2.3.2.130 or later. For NETGEAR XR700 versions 1.0.1.46 and earlier, update to version 1.0.1.46 or later.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00475
CVE-2021-45602

Affected Products

Netgear R7800
Netgear Ex2700
Netgear Lbr1020
Netgear Rbr20
Netgear R6700
Netgear R8900
Netgear R9000
Netgear Rax10
Netgear Rax120V1
Netgear Rax120V2
Netgear Rax70
Netgear Rax78
Netgear Wn3000Rpv2
Netgear Wn3000Rpv3
Netgear Xr450
Netgear Xr500
Netgear Xr700