PT-2021-5960 · NetGear · Rbs40+27

Aircut

·

Published

2021-09-25

·

Updated

2022-07-12

·

CVE-2021-45657

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR D6200 versions prior to 1.1.00.38 NETGEAR D7000 versions prior to 1.0.1.78 NETGEAR R6020 versions prior to 1.0.0.48 NETGEAR R6080 versions prior to 1.0.0.48 NETGEAR R6050 versions prior to 1.0.1.26 NETGEAR JR6150 versions prior to 1.0.1.26 NETGEAR R6120 versions prior to 1.0.0.66 NETGEAR R6220 versions prior to 1.1.0.100 NETGEAR R6230 versions prior to 1.1.0.100 NETGEAR R6260 versions prior to 1.1.0.78 NETGEAR R6800 versions prior to 1.2.0.76 NETGEAR R6900v2 versions prior to 1.2.0.76 NETGEAR R6700v2 versions prior to 1.2.0.76 NETGEAR R7450 versions prior to 1.2.0.76 NETGEAR AC2100 versions prior to 1.2.0.76 NETGEAR AC2400 versions prior to 1.2.0.76 NETGEAR AC2600 versions prior to 1.2.0.76 NETGEAR RBK40 versions prior to 2.5.1.16 NETGEAR RBR40 versions prior to 2.5.1.16 NETGEAR RBS40 versions prior to 2.5.1.16 NETGEAR RBK20 versions prior to 2.5.1.16 NETGEAR RBR20 versions prior to 2.5.1.16 NETGEAR RBS20 versions prior to 2.5.1.16 NETGEAR RBK50 versions prior to 2.5.1.16 NETGEAR RBR50 versions prior to 2.5.1.16 NETGEAR RBS50 versions prior to 2.5.1.16 NETGEAR RBS50Y versions prior to 2.6.1.40 NETGEAR WNR2020 versions prior to 1.1.0.62
Description The issue is related to incorrect management of code generation, which can lead to a server-side injection attack. This type of attack allows an attacker to inject malicious code into a server, potentially leading to unauthorized access or data manipulation. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For NETGEAR D6200 versions prior to 1.1.00.38, update to version 1.1.00.38 or later. For NETGEAR D7000 versions prior to 1.0.1.78, update to version 1.0.1.78 or later. For NETGEAR R6020 versions prior to 1.0.0.48, update to version 1.0.0.48 or later. For NETGEAR R6080 versions prior to 1.0.0.48, update to version 1.0.0.48 or later. For NETGEAR R6050 versions prior to 1.0.1.26, update to version 1.0.1.26 or later. For NETGEAR JR6150 versions prior to 1.0.1.26, update to version 1.0.1.26 or later. For NETGEAR R6120 versions prior to 1.0.0.66, update to version 1.0.0.66 or later. For NETGEAR R6220 versions prior to 1.1.0.100, update to version 1.1.0.100 or later. For NETGEAR R6230 versions prior to 1.1.0.100, update to version 1.1.0.100 or later. For NETGEAR R6260 versions prior to 1.1.0.78, update to version 1.1.0.78 or later. For NETGEAR R6800 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR R6900v2 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR R6700v2 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR R7450 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR AC2100 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR AC2400 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR AC2600 versions prior to 1.2.0.76, update to version 1.2.0.76 or later. For NETGEAR RBK40 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBR40 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBS40 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBK20 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBR20 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBS20 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBK50 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBR50 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBS50 versions prior to 2.5.1.16, update to version 2.5.1.16 or later. For NETGEAR RBS50Y versions prior to 2.6.1.40, update to version 2.6.1.40 or later. For NETGEAR WNR2020 versions prior to 1.1.0.62, update to version 1.1.0.62 or later.

Fix

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00478
CVE-2021-45657

Affected Products

Ac2100
Ac2400
Ac2600
D6200
D7000
Jr6150
R6020
R6050
R6080
R6120
R6220
R6230
R6260
R6700V2
R6800
R6900V2
R7450
Rbk20
Rbk40
Rbk50
Rbr20
Rbr40
Rbr50
Rbs20
Rbs40
Rbs50
Rbs50Y
Wnr2020