PT-2021-5957 · NetGear · Netgear R7800+16
Kevin Breen
·
Published
2021-05-03
·
Updated
2022-07-12
·
CVE-2021-45602
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR D7800 versions 1.0.1.66 and earlier
NETGEAR EX2700 versions 1.0.1.68 and earlier
NETGEAR WN3000RPv2 versions 1.0.0.90 and earlier
NETGEAR WN3000RPv3 versions 1.0.2.100 and earlier
NETGEAR LBR1020 versions 2.6.5.20 and earlier
NETGEAR LBR20 versions 2.6.5.32 and earlier
NETGEAR R6700AX versions 1.0.10.110 and earlier
NETGEAR R7800 versions 1.0.2.86 and earlier
NETGEAR R8900 versions 1.0.5.38 and earlier
NETGEAR R9000 versions 1.0.5.38 and earlier
NETGEAR RAX10 versions 1.0.10.110 and earlier
NETGEAR RAX120v1 versions 1.2.3.28 and earlier
NETGEAR RAX120v2 versions 1.2.3.28 and earlier
NETGEAR RAX70 versions 1.0.10.110 and earlier
NETGEAR RAX78 versions 1.0.10.110 and earlier
NETGEAR XR450 versions 2.3.2.130 and earlier
NETGEAR XR500 versions 2.3.2.130 and earlier
NETGEAR XR700 versions 1.0.1.46 and earlier
Description
The issue is related to command injection by an authenticated user due to the lack of input data sanitization. This can allow an attacker to execute arbitrary commands or gain unauthorized access to protected information by sending a specially crafted request to the UPNP port.
Recommendations
For NETGEAR D7800 versions 1.0.1.66 and earlier, update to version 1.0.1.66 or later.
For NETGEAR EX2700 versions 1.0.1.68 and earlier, update to version 1.0.1.68 or later.
For NETGEAR WN3000RPv2 versions 1.0.0.90 and earlier, update to version 1.0.0.90 or later.
For NETGEAR WN3000RPv3 versions 1.0.2.100 and earlier, update to version 1.0.2.100 or later.
For NETGEAR LBR1020 versions 2.6.5.20 and earlier, update to version 2.6.5.20 or later.
For NETGEAR LBR20 versions 2.6.5.32 and earlier, update to version 2.6.5.32 or later.
For NETGEAR R6700AX versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later.
For NETGEAR R7800 versions 1.0.2.86 and earlier, update to version 1.0.2.86 or later.
For NETGEAR R8900 versions 1.0.5.38 and earlier, update to version 1.0.5.38 or later.
For NETGEAR R9000 versions 1.0.5.38 and earlier, update to version 1.0.5.38 or later.
For NETGEAR RAX10 versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later.
For NETGEAR RAX120v1 versions 1.2.3.28 and earlier, update to version 1.2.3.28 or later.
For NETGEAR RAX120v2 versions 1.2.3.28 and earlier, update to version 1.2.3.28 or later.
For NETGEAR RAX70 versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later.
For NETGEAR RAX78 versions 1.0.10.110 and earlier, update to version 1.0.10.110 or later.
For NETGEAR XR450 versions 2.3.2.130 and earlier, update to version 2.3.2.130 or later.
For NETGEAR XR500 versions 2.3.2.130 and earlier, update to version 2.3.2.130 or later.
For NETGEAR XR700 versions 1.0.1.46 and earlier, update to version 1.0.1.46 or later.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear R7800
Netgear Ex2700
Netgear Lbr1020
Netgear Rbr20
Netgear R6700
Netgear R8900
Netgear R9000
Netgear Rax10
Netgear Rax120V1
Netgear Rax120V2
Netgear Rax70
Netgear Rax78
Netgear Wn3000Rpv2
Netgear Wn3000Rpv3
Netgear Xr450
Netgear Xr500
Netgear Xr700