PT-2021-6209 · NetGear · Netgear R7450+17
Published
2021-09-25
·
Updated
2022-01-10
·
CVE-2021-45551
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NETGEAR D6200 versions prior to 1.1.00.40
NETGEAR D7000 versions prior to 1.0.1.78
NETGEAR R6020 versions prior to 1.0.0.42
NETGEAR R6080 versions prior to 1.0.0.42
NETGEAR R6050 versions prior to 1.0.1.26
NETGEAR JR6150 versions prior to 1.0.1.26
NETGEAR R6120 versions prior to 1.0.0.66
NETGEAR R6220 versions prior to 1.1.0.110
NETGEAR R6230 versions prior to 1.1.0.110
NETGEAR R6260 versions prior to 1.1.0.64
NETGEAR R6800 versions prior to 1.2.0.62
NETGEAR R6700v2 versions prior to 1.2.0.62
NETGEAR R6900v2 versions prior to 1.2.0.62
NETGEAR R7450 versions prior to 1.2.0.62
NETGEAR AC2100 versions prior to 1.2.0.62
NETGEAR AC2400 versions prior to 1.2.0.62
NETGEAR AC2600 versions prior to 1.2.0.62
NETGEAR WNR2020 versions prior to 1.1.0.62
Description
The issue is related to the lack of input validation in the embedded software of certain NETGEAR devices, allowing for command injection by an authenticated user. This can enable a remote attacker to execute arbitrary commands.
Recommendations
For NETGEAR D6200 version prior to 1.1.00.40, update to version 1.1.00.40 or later.
For NETGEAR D7000 version prior to 1.0.1.78, update to version 1.0.1.78 or later.
For NETGEAR R6020 version prior to 1.0.0.42, update to version 1.0.0.42 or later.
For NETGEAR R6080 version prior to 1.0.0.42, update to version 1.0.0.42 or later.
For NETGEAR R6050 version prior to 1.0.1.26, update to version 1.0.1.26 or later.
For NETGEAR JR6150 version prior to 1.0.1.26, update to version 1.0.1.26 or later.
For NETGEAR R6120 version prior to 1.0.0.66, update to version 1.0.0.66 or later.
For NETGEAR R6220 version prior to 1.1.0.110, update to version 1.1.0.110 or later.
For NETGEAR R6230 version prior to 1.1.0.110, update to version 1.1.0.110 or later.
For NETGEAR R6260 version prior to 1.1.0.64, update to version 1.1.0.64 or later.
For NETGEAR R6800 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR R6700v2 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR R6900v2 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR R7450 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR AC2100 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR AC2400 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR AC2600 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For NETGEAR WNR2020 version prior to 1.1.0.62, update to version 1.1.0.62 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Ac2100
Netgear Ac2400
Netgear Ac2600
Netgear D6200
Netgear R7000
Netgear Jr6150
Netgear R6020
Netgear R6050
Netgear R6080
Netgear R6120
Netgear R6220
Netgear R6230
Netgear R6260
Netgear R6700V2
Netgear R6800
Netgear R6900V2
Netgear R7450
Netgear Wnr2020