PT-2021-6182 · NetGear · Rbs40+27

Crixer

·

Published

2021-12-20

·

Updated

2022-01-10

·

CVE-2021-45548

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NETGEAR D7800 versions prior to 1.0.1.60 NETGEAR DM200 versions prior to 1.0.0.66 NETGEAR EX2700 versions prior to 1.0.1.56 NETGEAR EX6150v2 versions prior to 1.0.1.86 NETGEAR EX6200v2 versions prior to 1.0.1.86 NETGEAR EX6250 versions prior to 1.0.0.128 NETGEAR EX6400 versions prior to 1.0.2.144 NETGEAR EX6400v2 versions prior to 1.0.0.128 NETGEAR EX6410 versions prior to 1.0.0.128 NETGEAR EX6420 versions prior to 1.0.0.128 NETGEAR EX7300 versions prior to 1.0.2.144 NETGEAR EX7300v2 versions prior to 1.0.0.128 NETGEAR EX7320 versions prior to 1.0.0.128 NETGEAR R7500v2 versions prior to 1.0.3.46 NETGEAR R7800 versions prior to 1.0.2.74 NETGEAR R8900 versions prior to 1.0.5.26 NETGEAR R9000 versions prior to 1.0.5.2 NETGEAR RAX120 versions prior to 1.0.1.128 NETGEAR WN3000RPv2 versions prior to 1.0.0.78 NETGEAR WN3000RPv3 versions prior to 1.0.2.80 NETGEAR WNR2000v5 versions prior to 1.0.0.74 NETGEAR XR500 versions prior to 2.3.2.66 NETGEAR RBK20 versions prior to 2.7.3.22 NETGEAR RBR20 versions prior to 2.7.3.22 NETGEAR RBS20 versions prior to 2.7.3.22 NETGEAR RBK40 versions prior to 2.7.3.22 NETGEAR RBR40 versions prior to 2.7.3.22 NETGEAR RBS40 versions prior to 2.7.3.22
Description The issue is related to the lack of input data sanitization, which can allow a remote attacker to execute arbitrary commands. This is a command injection vulnerability that affects certain NETGEAR devices.
Recommendations Update NETGEAR D7800 to version 1.0.1.60 or later Update NETGEAR DM200 to version 1.0.0.66 or later Update NETGEAR EX2700 to version 1.0.1.56 or later Update NETGEAR EX6150v2 to version 1.0.1.86 or later Update NETGEAR EX6200v2 to version 1.0.1.86 or later Update NETGEAR EX6250 to version 1.0.0.128 or later Update NETGEAR EX6400 to version 1.0.2.144 or later Update NETGEAR EX6400v2 to version 1.0.0.128 or later Update NETGEAR EX6410 to version 1.0.0.128 or later Update NETGEAR EX6420 to version 1.0.0.128 or later Update NETGEAR EX7300 to version 1.0.2.144 or later Update NETGEAR EX7300v2 to version 1.0.0.128 or later Update NETGEAR EX7320 to version 1.0.0.128 or later Update NETGEAR R7500v2 to version 1.0.3.46 or later Update NETGEAR R7800 to version 1.0.2.74 or later Update NETGEAR R8900 to version 1.0.5.26 or later Update NETGEAR R9000 to version 1.0.5.2 or later Update NETGEAR RAX120 to version 1.0.1.128 or later Update NETGEAR WN3000RPv2 to version 1.0.0.78 or later Update NETGEAR WN3000RPv3 to version 1.0.2.80 or later Update NETGEAR WNR2000v5 to version 1.0.0.74 or later Update NETGEAR XR500 to version 2.3.2.66 or later Update NETGEAR RBK20 to version 2.7.3.22 or later Update NETGEAR RBR20 to version 2.7.3.22 or later Update NETGEAR RBS20 to version 2.7.3.22 or later Update NETGEAR RBK40 to version 2.7.3.22 or later Update NETGEAR RBR40 to version 2.7.3.22 or later Update NETGEAR RBS40 to version 2.7.3.22 or later

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01098
CVE-2021-45548

Affected Products

D7800
Dm200
Ex2700
Ex6150V2
Ex6200V2
Ex6250
Ex6400
Ex6400V2
Ex6410
Ex6420
Ex7300
Ex7300V2
Ex7320
R7500V2
R7800
R8900
R9000
Rax120
Rbk20
Rbk40
Rbr20
Rbr40
Rbs20
Rbs40
Wn3000Rpv2
Wn3000Rpv3
Wnr2000V5
Xr500